PT-2023-23958 · Synapse+3 · Synapse+3
Rikjohnston
·
Published
2023-06-06
·
Updated
2025-04-22
·
CVE-2023-32683
CVSS v4.0
5.1
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Synapse versions prior to 1.85.0
Description
A discovered oEmbed or image URL can bypass the
url preview url blacklist setting, potentially allowing server-side request forgery or bypassing network policies. The impact is limited to IP addresses allowed by the url preview ip range blacklist setting and by the limited information returned to the client. For discovered oEmbed URLs, any non-JSON response or a JSON response that includes non-oEmbed information is discarded. For discovered image URLs, any non-image response is discarded. Systems with URL preview disabled or without a configured url preview url blacklist are not affected.Recommendations
For versions prior to 1.85.0, upgrade to version 1.85.0 to resolve the issue.
As a temporary workaround, consider disabling URL previews by setting
url preview enabled to False until a patch is available.
Restrict access to the url preview ip range blacklist setting to minimize the risk of exploitation.
Avoid using the url preview url blacklist setting in configurations where it may be bypassed until the issue is resolved.Exploit
Fix
SSRF
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Linuxmint
Synapse
Ubuntu