Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:44090
HistoryNov 01, 2023 - 8:58 a.m.

Information Disclosure

2023-11-0108:58:43
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11
matrix_synapse
information disclosure
vulnerability
missing validation check
user_id parameter
remote users

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

6.8

Confidence

Low

EPSS

0.001

Percentile

47.7%

matrix_synapse is vulnerable to Information Disclosure. The vulnerability is caused by a missing validation check for the user_id parameter used to query cached device information of remote users. This can lead to enumerating the remote users known to a homeserver.

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

6.8

Confidence

Low

EPSS

0.001

Percentile

47.7%