Lucene search

K
osvGoogleOSV:CVE-2023-41335
HistorySep 27, 2023 - 3:19 p.m.

CVE-2023-41335

2023-09-2715:19:30
Google
osv.dev
8
cve-2023-41335
matrix homeserver
password storage

AI Score

7

Confidence

High

EPSS

0.001

Percentile

30.1%

Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. When users update their passwords, the new credentials may be briefly held in the server database. While this doesnโ€™t grant the server any added capabilitiesโ€”it already learns the usersโ€™ passwords as part of the authentication processโ€”it does disrupt the expectation that passwords wonโ€™t be stored in the database. As a result, these passwords could inadvertently be captured in database backups for a longer duration. These temporarily stored passwords are automatically erased after a 48-hour window. This issue has been addressed in version 1.93.0. Users are advised to upgrade. There are no known workarounds for this issue.

AI Score

7

Confidence

High

EPSS

0.001

Percentile

30.1%