CVE-2021-29471
published 2021-05-11CVE-2021-29471: Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP…
PriorityP428medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
1.65%
73.8th percentile
Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.33.2 "Push rules" can specify conditions under which they will match, including `event_match`, which matches event content against a pattern including wildcards. Certain patterns can cause very poor performance in the matching engine, leading to a denial-of-service when processing moderate length events. The issue is patched in version 1.33.2. A potential workaround might be to prevent users from making custom push rules, by blocking such requests at a reverse-proxy.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | matrix-synapse | < matrix-synapse 1.33.2-1 (forky) | matrix-synapse 1.33.2-1 (forky) |
| fedoraproject | fedora | — | — |
| matrix-org | synapse | < 1.33.2 | 1.33.2 |
| matrix | synapse | < 1.33.2 | 1.33.2 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.3MEDIUM
vendor_debian3.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2021-29471: matrix-synapse - Synapse is a Matrix reference homeserver written in python (pypi package matrix-...
vendor_debian·2021·CVSS 3.7
CVE-2021-29471 [LOW] CVE-2021-29471: matrix-synapse - Synapse is a Matrix reference homeserver written in python (pypi package matrix-...
Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.33.2 "Push rules" can specify conditions under which they will match, including `event_match`, which matches event content against a pattern including wildcards. Certain patterns can cause very poor performance in the matching engine, leading to a denial-of-service when processing moderate length events. The issue is patched in version 1.33.2. A potential workaround might be to prevent users from making custom push rules, by blocking such requests at a reverse-proxy.
Scope: local
forky: resolved (fixed in 1.33.2-1)
sid: resolved (fixed in 1.33.2-1)
GHSA
Denial of service attack via push rule patterns in matrix-synapse
ghsa·2021-05-13
CVE-2021-29471 [MEDIUM] CWE-331 Denial of service attack via push rule patterns in matrix-synapse
Denial of service attack via push rule patterns in matrix-synapse
### Impact
"Push rules" can specify [conditions](https://matrix.org/docs/spec/client_server/r0.6.1#conditions) under which they will match, including `event_match`, which matches event content against a pattern including wildcards.
Certain patterns can cause very poor performance in the matching engine, leading to a denial-of-service when processing moderate length events.
### Patches
The issue is patched by https://github.com/matrix-org/synapse/commit/03318a766cac9f8b053db2214d9c332a977d226c.
### Workarounds
A potential workaround might be to prevent users from making custom push rules, by blocking such requests at a reverse-proxy.
### For more information
If you have any questions or comments about this advisory,
OSV
Denial of service attack via push rule patterns in matrix-synapse
osv·2021-05-13
CVE-2021-29471 [MEDIUM] Denial of service attack via push rule patterns in matrix-synapse
Denial of service attack via push rule patterns in matrix-synapse
### Impact
"Push rules" can specify [conditions](https://matrix.org/docs/spec/client_server/r0.6.1#conditions) under which they will match, including `event_match`, which matches event content against a pattern including wildcards.
Certain patterns can cause very poor performance in the matching engine, leading to a denial-of-service when processing moderate length events.
### Patches
The issue is patched by https://github.com/matrix-org/synapse/commit/03318a766cac9f8b053db2214d9c332a977d226c.
### Workarounds
A potential workaround might be to prevent users from making custom push rules, by blocking such requests at a reverse-proxy.
### For more information
If you have any questions or comments about this advisory,
OSV
CVE-2021-29471: Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse)
osv·2021-05-11·CVSS 5.3
CVE-2021-29471 [MEDIUM] CVE-2021-29471: Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse)
Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.33.2 "Push rules" can specify conditions under which they will match, including `event_match`, which matches event content against a pattern including wildcards. Certain patterns can cause very poor performance in the matching engine, leading to a denial-of-service when processing moderate length events. The issue is patched in version 1.33.2. A potential workaround might be to prevent users from making custom push rules, by blocking such requests at a reverse-proxy.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/matrix-org/synapse/commit/03318a766cac9f8b053db2214d9c332a977d226chttps://github.com/matrix-org/synapse/releases/tag/v1.33.2https://github.com/matrix-org/synapse/security/advisories/GHSA-x345-32rc-8h85https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TNNAJOZNMVMXM6AS7RFFKB4QLUJ4IFEY/https://github.com/matrix-org/synapse/commit/03318a766cac9f8b053db2214d9c332a977d226chttps://github.com/matrix-org/synapse/releases/tag/v1.33.2https://github.com/matrix-org/synapse/security/advisories/GHSA-x345-32rc-8h85https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TNNAJOZNMVMXM6AS7RFFKB4QLUJ4IFEY/
2021-05-11
Published