Lucene search

K
ubuntucveUbuntu.comUB:CVE-2020-26890
HistoryNov 24, 2020 - 12:00 a.m.

CVE-2020-26890

2020-11-2400:00:00
ubuntu.com
ubuntu.com
19
cve-2020-26890
json values
denial of service

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.007

Percentile

80.5%

Matrix Synapse before 1.20.0 erroneously permits non-standard NaN,
Infinity, and -Infinity JSON values in fields of m.room.member events,
allowing remote attackers to execute a denial of service attack against the
federation and common Matrix clients. If such a malformed event is accepted
into the room’s state, the impact is long-lasting and is not fixed by an
upgrade to a newer version, requiring the event to be manually redacted
instead. Since events are replicated to servers of other room members, the
impact is not constrained to the server of the event sender.

OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchmatrix-synapse< anyUNKNOWN
ubuntu20.04noarchmatrix-synapse< anyUNKNOWN

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.007

Percentile

80.5%