CVE-2023-45129
Summary
| CVE | CVE-2023-45129 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-10-10 18:15:00 UTC |
| Updated | 2024-01-07 11:15:00 UTC |
| Description | Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. Prior to version 1.94.0, a malicious server ACL event can impact performance temporarily or permanently leading to a persistent denial of service. Homeservers running on a closed federation (which presumably do not need to use server ACLs) are not affected. Server administrators are advised to upgrade to Synapse 1.94.0 or later. As a workaround, rooms with malicious server ACL events can be purged and blocked using the admin API. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 39 Update: matrix-synapse-1.94.0-2.fc39 - package-announce - Fedora Mailing-Lists |
MISC |
lists.fedoraproject.org |
|
| Rooms - Synapse |
MISC |
matrix-org.github.io |
|
| [SECURITY] Fedora 37 Update: matrix-synapse-1.80.0-7.fc37 - package-announce - Fedora Mailing-Lists |
MISC |
lists.fedoraproject.org |
|
| Add a cache around server ACL checking by clokep · Pull Request #16360 · matrix-org/synapse · GitHub |
MISC |
github.com |
|
| security.gentoo.org/glsa/202401-12 |
|
security.gentoo.org |
|
| Denial of service due to malicious server ACL events · Advisory · matrix-org/synapse · GitHub |
MISC |
github.com |
|
| [SECURITY] Fedora 38 Update: matrix-synapse-1.94.0-2.fc38 - package-announce - Fedora Mailing-Lists |
MISC |
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 284642 Fedora Security Update for matrix (FEDORA-2023-c3c8cc5f8b)
- 284661 Fedora Security Update for matrix (FEDORA-2023-954c2ec5bd)
- 285204 Fedora Security Update for matrix (FEDORA-2023-4d4c73a8f0)
- 503384 Alpine Linux Security Update for synapse
- 506256 Alpine Linux Security Update for synapse
- 710826 Gentoo Linux Synapse Multiple Vulnerabilities (GLSA 202401-12)
- 995561 Python (Pip) Security Update for matrix-synapse (GHSA-5chr-wjw5-3gq4)