PT-2023-23730 · Synapse+1 · Synapse+1

Moderatedkasak

·

Published

2023-05-24

·

Updated

2023-09-18

·

CVE-2023-32323

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:L
Name of the Vulnerable Software and Affected Versions Synapse versions up to and including 1.73
Description A malicious user on a Synapse homeserver with permission to create certain state events can disable outbound federation from one homeserver to another. This is possible due to the lack of size limitation on the invite room state field in Synapse versions up to and including 1.73, allowing for the creation of an arbitrarily large invite event. Synapse instances with federation disabled are not affected.
Recommendations For Synapse versions up to and including 1.73, upgrade to Synapse 1.74 or newer urgently. As a partial mitigation, Synapse operators can disable open registration to limit the ability of attackers to create new accounts on the homeserver. If the homeserver has been attacked, restarting it will resume outgoing federation by entering "catchup mode", but this does not prevent the attacker from repeating their attack.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

ALT-PU-2023-4748
CVE-2023-32323
GHSA-F3WC-3VXV-XMVR
PYSEC-2023-67

Affected Products

Alt Linux
Synapse