CVE-2020-26257
published 2020-12-09CVE-2020-26257: Matrix is an ecosystem for open federated Instant Messaging and VoIP. Synapse is a reference "homeserver" implementation of Matrix. A malicious or…
PriorityP434medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
2.36%
81.9th percentile
Matrix is an ecosystem for open federated Instant Messaging and VoIP. Synapse is a reference "homeserver" implementation of Matrix. A malicious or poorly-implemented homeserver can inject malformed events into a room by specifying a different room id in the path of a `/send_join`, `/send_leave`, `/invite` or `/exchange_third_party_invite` request. This can lead to a denial of service in which future events will not be correctly sent to other servers over federation. This affects any server which accepts federation requests from untrusted servers. The Matrix Synapse reference implementation before version 1.23.1 the implementation is vulnerable to this injection attack. Issue is fixed in version 1.23.1. As a workaround homeserver administrators could limit access to the federation API to trusted servers (for example via `federation_domain_whitelist`).
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | matrix-synapse | < matrix-synapse 1.24.0-1 (forky) | matrix-synapse 1.24.0-1 (forky) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| matrix-org | synapse | < 1.23.1 | 1.23.1 |
| matrix | synapse | < 1.23.1 | 1.23.1 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Denial of service attack via incorrect parameters in Matrix Synapse
ghsa·2020-12-09
CVE-2020-26257 [HIGH] CWE-400 Denial of service attack via incorrect parameters in Matrix Synapse
Denial of service attack via incorrect parameters in Matrix Synapse
### Impact
A malicious or poorly-implemented homeserver can inject malformed events into a room by specifying a different room id in the path of a `/send_join`, `/send_leave`, `/invite` or `/exchange_third_party_invite` request.
This can lead to a denial of service in which future events will not be correctly sent to other servers over federation.
This affects any server which accepts federation requests from untrusted servers.
### Patches
Issue is resolved by https://github.com/matrix-org/synapse/pull/8776.
### Workarounds
Homeserver administrators could limit access to the federation API to trusted servers (for example via `federation_domain_whitelist`).
OSV
CVE-2020-26257: Matrix is an ecosystem for open federated Instant Messaging and VoIP
osv·2020-12-09·CVSS 6.5
CVE-2020-26257 [MEDIUM] CVE-2020-26257: Matrix is an ecosystem for open federated Instant Messaging and VoIP
Matrix is an ecosystem for open federated Instant Messaging and VoIP. Synapse is a reference "homeserver" implementation of Matrix. A malicious or poorly-implemented homeserver can inject malformed events into a room by specifying a different room id in the path of a `/send_join`, `/send_leave`, `/invite` or `/exchange_third_party_invite` request. This can lead to a denial of service in which future events will not be correctly sent to other servers over federation. This affects any server which accepts federation requests from untrusted servers. The Matrix Synapse reference implementation before version 1.23.1 the implementation is vulnerable to this injection attack. Issue is fixed in version 1.23.1. As a workaround homeserver administrators could limit access to the federation API to tr
OSV
Denial of service attack via incorrect parameters in Matrix Synapse
osv·2020-12-09
CVE-2020-26257 [HIGH] Denial of service attack via incorrect parameters in Matrix Synapse
Denial of service attack via incorrect parameters in Matrix Synapse
### Impact
A malicious or poorly-implemented homeserver can inject malformed events into a room by specifying a different room id in the path of a `/send_join`, `/send_leave`, `/invite` or `/exchange_third_party_invite` request.
This can lead to a denial of service in which future events will not be correctly sent to other servers over federation.
This affects any server which accepts federation requests from untrusted servers.
### Patches
Issue is resolved by https://github.com/matrix-org/synapse/pull/8776.
### Workarounds
Homeserver administrators could limit access to the federation API to trusted servers (for example via `federation_domain_whitelist`).
Debian
CVE-2020-26257: matrix-synapse - Matrix is an ecosystem for open federated Instant Messaging and VoIP. Synapse is...
vendor_debian·2020·CVSS 6.5
CVE-2020-26257 [MEDIUM] CVE-2020-26257: matrix-synapse - Matrix is an ecosystem for open federated Instant Messaging and VoIP. Synapse is...
Matrix is an ecosystem for open federated Instant Messaging and VoIP. Synapse is a reference "homeserver" implementation of Matrix. A malicious or poorly-implemented homeserver can inject malformed events into a room by specifying a different room id in the path of a `/send_join`, `/send_leave`, `/invite` or `/exchange_third_party_invite` request. This can lead to a denial of service in which future events will not be correctly sent to other servers over federation. This affects any server which accepts federation requests from untrusted servers. The Matrix Synapse reference implementation before version 1.23.1 the implementation is vulnerable to this injection attack. Issue is fixed in version 1.23.1. As a workaround homeserver administrators could limit access to the federation API to tr
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/matrix-org/synapse/blob/develop/CHANGES.md#synapse-1231-2020-12-09https://github.com/matrix-org/synapse/commit/3ce2f303f15f6ac3dc352298972dc6e04d9b7a8bhttps://github.com/matrix-org/synapse/pull/8776https://github.com/matrix-org/synapse/security/advisories/GHSA-hxmp-pqch-c8mmhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DBTIU3ZNBFWZ56V4X7JIAD33V5H2GOMC/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QR4MMYZKX5N5GYGH4H5LBUUC5TLAFHI7/https://github.com/matrix-org/synapse/blob/develop/CHANGES.md#synapse-1231-2020-12-09https://github.com/matrix-org/synapse/commit/3ce2f303f15f6ac3dc352298972dc6e04d9b7a8bhttps://github.com/matrix-org/synapse/pull/8776https://github.com/matrix-org/synapse/security/advisories/GHSA-hxmp-pqch-c8mmhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DBTIU3ZNBFWZ56V4X7JIAD33V5H2GOMC/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QR4MMYZKX5N5GYGH4H5LBUUC5TLAFHI7/
2020-12-09
Published