PT-2021-4112 · Synapse+1 · Synapse+1

Richvdh

·

Published

2021-03-30

·

Updated

2024-06-15

·

CVE-2021-29471

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Synapse versions prior to 1.33.2
Description The issue is related to uncontrolled resource consumption in Synapse's push rules. It allows a remote attacker to cause a denial-of-service. The problem arises when certain patterns, including wildcards, are used in the event match condition, leading to poor performance in the matching engine when processing moderate length events.
Recommendations For versions prior to 1.33.2, update to version 1.33.2 to resolve the issue. As a temporary workaround, consider preventing users from making custom push rules by blocking such requests at a reverse-proxy.

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1971
BDU:2021-04702
CVE-2021-29471
GHSA-X345-32RC-8H85
OPENSUSE-SU-2024:11041-1
PYSEC-2021-135

Affected Products

Alt Linux
Synapse