Lucene search

K
githubGitHub Advisory DatabaseGHSA-MP92-3JFM-3575
HistoryOct 31, 2023 - 8:29 p.m.

Synapse vulnerable to leak of remote user device information

2023-10-3120:29:49
CWE-200
GitHub Advisory Database
github.com
10
synapse
vulnerability
remote user
device information
leak
homeserver
upgrade
patch
federation
traffic
whitelist

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

5.2

Confidence

High

EPSS

0.001

Percentile

47.7%

Impact

Cached device information of remote users can be queried from Synapse. This can be used to enumerate the remote users known to a homeserver.

Patches

System administrators are encouraged to upgrade to Synapse 1.95.1 as soon as possible.

Workarounds

The federation_domain_whitelist can be used to limit federation traffic with a homeserver.

Affected configurations

Vulners
Node
matrixsynapseRange<1.95.1
VendorProductVersionCPE
matrixsynapse*cpe:2.3:a:matrix:synapse:*:*:*:*:*:*:*:*

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

5.2

Confidence

High

EPSS

0.001

Percentile

47.7%