PT-2024-27461 · Matrix · Synapse
Published
2024-12-03
·
Updated
2025-08-26
·
CVE-2024-37303
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Synapse versions prior to 1.106
Description
Synapse, an open-source Matrix homeserver, allows unauthenticated remote participants to trigger a download and caching of remote media from a remote homeserver to the local media repository. This functionality enables unauthenticated remote adversaries to plant problematic content into the media repository, making it available for download from the local homeserver in an unauthenticated way. A partial mitigation is introduced in Synapse version 1.106, which includes new endpoints requiring authentication for media downloads. The unauthenticated endpoints will be frozen in a future release, closing the attack vector.
Recommendations
For Synapse versions prior to 1.106, update to version 1.106 or later to introduce partial mitigation through new authenticated endpoints for media downloads.
As a temporary workaround, consider using more strict rate limits based on IP address to limit the potential impact.
Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Synapse