CVE-2022-39374
published 2023-05-26CVE-2022-39374: Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. If Synapse and a malicious homeserver are both joined to the…
PriorityP431medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
0.94%
57.1th percentile
Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. If Synapse and a malicious homeserver are both joined to the same room, the malicious homeserver can trick Synapse into accepting previously rejected events into its view of the current state of that room. This can be exploited in a way that causes all further messages and state changes sent in that room from the vulnerable homeserver to be rejected. This issue has been patched in version 1.68.0
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | matrix-synapse | < matrix-synapse 1.68.0-1 (forky) | matrix-synapse 1.68.0-1 (forky) |
| matrix-org | synapse | — | — |
| matrix | synapse | >= 1.62.0 < 1.68.0 | 1.68.0 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
matrix-synapse vulnerabilities
osv·2025-04-22·CVSS 5.0
CVE-2023-32683 [MEDIUM] matrix-synapse vulnerabilities
matrix-synapse vulnerabilities
It was discovered that Synapse network policies could be bypassed via
specially crafted URLs. An attacker could possibly use this issue to
bypass authentication mechanisms. (CVE-2023-32683)
It was discovered that Synapse exposed cached device information. An
attacker could possibly use this issue to gain access to sensitive
information. (CVE-2023-43796)
It was discovered that Synapse could be tricked into rejecting state
changes in rooms. An attacker could possibly use this issue to cause
Synapse to stop functioning properly, resulting in a denial of service.
This issue was only fixed in Ubuntu 20.04 LTS and Ubuntu 22.04 LTS.
(CVE-2022-39374)
It was discovered that Synapse stored user credentials in a server's
database temporarily. An attacker could possi
OSV
CVE-2022-39374: Synapse is an open-source Matrix homeserver written and maintained by the Matrix
osv·2023-05-26·CVSS 6.5
CVE-2022-39374 [MEDIUM] CVE-2022-39374: Synapse is an open-source Matrix homeserver written and maintained by the Matrix
Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. If Synapse and a malicious homeserver are both joined to the same room, the malicious homeserver can trick Synapse into accepting previously rejected events into its view of the current state of that room. This can be exploited in a way that causes all further messages and state changes sent in that room from the vulnerable homeserver to be rejected. This issue has been patched in version 1.68.0
GHSA
Synapse Denial of service due to incorrect application of event authorization rules during state resolution
ghsa·2023-05-24
CVE-2022-39374 [HIGH] CWE-400 Synapse Denial of service due to incorrect application of event authorization rules during state resolution
Synapse Denial of service due to incorrect application of event authorization rules during state resolution
### Impact
If Synapse and a malicious homeserver are both joined to the same room, the malicious homeserver can trick Synapse into accepting previously rejected events into its view of the current state of that room. This can be exploited in a way that causes all further messages and state changes sent in that room from the vulnerable homeserver to be rejected.
Synapse homeservers are affected by this issue if and only if they are joined to rooms which members of untrusted homeservers are joined or invited to.
- Synapse homeservers in rooms available over public federation **are** affected.
- Synapse homeservers with federation disabled are not affected.
- Synapse homeservers in a
OSV
Synapse Denial of service due to incorrect application of event authorization rules during state resolution
osv·2023-05-24
CVE-2022-39374 [HIGH] Synapse Denial of service due to incorrect application of event authorization rules during state resolution
Synapse Denial of service due to incorrect application of event authorization rules during state resolution
### Impact
If Synapse and a malicious homeserver are both joined to the same room, the malicious homeserver can trick Synapse into accepting previously rejected events into its view of the current state of that room. This can be exploited in a way that causes all further messages and state changes sent in that room from the vulnerable homeserver to be rejected.
Synapse homeservers are affected by this issue if and only if they are joined to rooms which members of untrusted homeservers are joined or invited to.
- Synapse homeservers in rooms available over public federation **are** affected.
- Synapse homeservers with federation disabled are not affected.
- Synapse homeservers in a
Ubuntu
Synapse vulnerabilities
vendor_ubuntu·2025-04-22·CVSS 5.0
CVE-2023-41335 [MEDIUM] Synapse vulnerabilities
Title: Synapse vulnerabilities
Summary: Several security issues were fixed in Synapse.
It was discovered that Synapse network policies could be bypassed via
specially crafted URLs. An attacker could possibly use this issue to
bypass authentication mechanisms. (CVE-2023-32683)
It was discovered that Synapse exposed cached device information. An
attacker could possibly use this issue to gain access to sensitive
information. (CVE-2023-43796)
It was discovered that Synapse could be tricked into rejecting state
changes in rooms. An attacker could possibly use this issue to cause
Synapse to stop functioning properly, resulting in a denial of service.
This issue was only fixed in Ubuntu 20.04 LTS and Ubuntu 22.04 LTS.
(CVE-2022-39374)
It was discovered that Synapse stored user credentials in
Debian
CVE-2022-39374: matrix-synapse - Synapse is an open-source Matrix homeserver written and maintained by the Matrix...
vendor_debian·2022·CVSS 6.5
CVE-2022-39374 [MEDIUM] CVE-2022-39374: matrix-synapse - Synapse is an open-source Matrix homeserver written and maintained by the Matrix...
Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. If Synapse and a malicious homeserver are both joined to the same room, the malicious homeserver can trick Synapse into accepting previously rejected events into its view of the current state of that room. This can be exploited in a way that causes all further messages and state changes sent in that room from the vulnerable homeserver to be rejected. This issue has been patched in version 1.68.0
Scope: local
forky: resolved (fixed in 1.68.0-1)
sid: resolved (fixed in 1.68.0-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/matrix-org/synapse/pull/13723https://github.com/matrix-org/synapse/security/advisories/GHSA-p9qp-c452-f9r7https://lists.fedoraproject.org/archives/list/[email protected]/message/UJIJRP5ZH6B3KGFLHCAKR2IX2Y4Z25QD/https://github.com/matrix-org/synapse/pull/13723https://github.com/matrix-org/synapse/security/advisories/GHSA-p9qp-c452-f9r7https://lists.fedoraproject.org/archives/list/[email protected]/message/UJIJRP5ZH6B3KGFLHCAKR2IX2Y4Z25QD/
2023-05-26
Published