CVE-2022-31152Improper Check or Handling of Exceptional Conditions in Synapse

Severity
7.5HIGHNVD
CNA6.4
EPSS
0.7%
top 27.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 2

Description

Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. The Matrix specification specifies a list of [event authorization rules](https://spec.matrix.org/v1.2/rooms/v9/#authorization-rules) which must be checked when determining if an event should be accepted into a room. In versions of Synapse up to and including version 1.61.0, some of these rules are not correctly applied. An attacker could craft events which would be accepted by Synapse but not a spec-

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

NVDmatrix/synapse< 1.62.0
CVEListV5matrix-org/synapse< 1.62.0

Patches

🔴Vulnerability Details

4
CVEList
Synapse vulnerable to denial of service (DoS) due to incorrect application of event authorization rules2022-09-02
OSV
CVE-2022-31152: Synapse is an open-source Matrix homeserver written and maintained by the Matrix2022-09-02
GHSA
Denial of service due to incorrect application of event authorization rules2022-08-31
OSV
Denial of service due to incorrect application of event authorization rules2022-08-31

📋Vendor Advisories

1
Debian
CVE-2022-31152: matrix-synapse - Synapse is an open-source Matrix homeserver written and maintained by the Matrix...2022
CVE-2022-31152 — Matrix-org Synapse vulnerability | cvebase