PT-2021-4112 · Synapse+1 · Synapse+1
Richvdh
·
Published
2021-03-30
·
Updated
2024-06-15
·
CVE-2021-29471
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Synapse versions prior to 1.33.2
Description
The issue is related to uncontrolled resource consumption in Synapse's push rules. It allows a remote attacker to cause a denial-of-service. The problem arises when certain patterns, including wildcards, are used in the
event match condition, leading to poor performance in the matching engine when processing moderate length events.Recommendations
For versions prior to 1.33.2, update to version 1.33.2 to resolve the issue.
As a temporary workaround, consider preventing users from making custom push rules by blocking such requests at a reverse-proxy.
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Synapse