PT-2024-27461 · Matrix · Synapse

Published

2024-12-03

·

Updated

2025-08-26

·

CVE-2024-37303

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Synapse versions prior to 1.106
Description Synapse, an open-source Matrix homeserver, allows unauthenticated remote participants to trigger a download and caching of remote media from a remote homeserver to the local media repository. This functionality enables unauthenticated remote adversaries to plant problematic content into the media repository, making it available for download from the local homeserver in an unauthenticated way. A partial mitigation is introduced in Synapse version 1.106, which includes new endpoints requiring authentication for media downloads. The unauthenticated endpoints will be frozen in a future release, closing the attack vector.
Recommendations For Synapse versions prior to 1.106, update to version 1.106 or later to introduce partial mitigation through new authenticated endpoints for media downloads. As a temporary workaround, consider using more strict rate limits based on IP address to limit the potential impact.

Exploit

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-37303
GHSA-GJGR-7834-RHXR
OPENSUSE-SU-2024:14541-1
PYSEC-2024-287

Affected Products

Synapse