PT-2020-16383 · Matrix+1 · Matrix Synapse+1

Erikjohnston

·

Published

2020-12-09

·

Updated

2024-06-15

·

CVE-2020-26257

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Matrix Synapse versions prior to 1.23.1
Description A malicious or poorly-implemented homeserver can inject malformed events into a room by specifying a different room id in the path of API endpoints such as /send join, /send leave, /invite, or /exchange third party invite. This can lead to a denial of service in which future events will not be correctly sent to other servers over federation. The issue affects any server that accepts federation requests from untrusted servers.
Recommendations For versions prior to 1.23.1, update to version 1.23.1 to resolve the issue. As a temporary workaround, homeserver administrators could limit access to the federation API to trusted servers, for example via federation domain whitelist.

Fix

DoS

Special Elements Injection

XSS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1385
CVE-2020-26257
GHSA-HXMP-PQCH-C8MM
OPENSUSE-SU-2024:11041-1
PYSEC-2020-236

Affected Products

Alt Linux
Matrix Synapse