PT-2023-13719 · Synapse+3 · Synapse+3

Kasak

·

Published

2023-05-24

·

Updated

2025-04-22

·

CVE-2022-39335

CVSS v4.0

7.7

High

VectorAV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Synapse versions up to and including 1.68.0
Description The Matrix Federation API in Synapse allows remote homeservers to request authorization events in a room, which is necessary for validating the legitimacy and permission of events. However, in affected versions, a Synapse homeserver does not sufficiently check if the requesting server should be able to access these events. This issue can be exploited when a malicious actor knows the ID of a target room and the ID of an event from that room. The issue is of negligible consequence for public rooms and deployments in a closed federation where all homeservers are trustworthy.
Recommendations For Synapse versions up to and including 1.68.0, upgrade to Synapse 1.69.0 to resolve the issue. As a temporary workaround, consider configuring Synapse with a list of trusted servers using the federation domain whitelist to restrict access, but this is not practical for homeservers participating in open federation.

Exploit

Fix

Missing Authorization

Information Disclosure

Weakness Enumeration

Related Identifiers

ALT-PU-2023-4748
CVE-2022-39335
GHSA-45CJ-F97F-GGWV
PYSEC-2023-65
USN-7444-1

Affected Products

Alt Linux
Linuxmint
Synapse
Ubuntu