CVE-2023-32683
published 2023-06-06CVE-2023-32683: Synapse is a Matrix protocol homeserver written in Python with the Twisted framework. A discovered oEmbed or image URL can bypass the…
PriorityP429medium5.4CVSS 3.1
AVNACLPRLUINSUCLILAN
EPSS
0.60%
45.0th percentile
Synapse is a Matrix protocol homeserver written in Python with the Twisted framework. A discovered oEmbed or image URL can bypass the `url_preview_url_blacklist` setting potentially allowing server side request forgery or bypassing network policies. Impact is limited to IP addresses allowed by the `url_preview_ip_range_blacklist` setting (by default this only allows public IPs) and by the limited information returned to the client: 1. For discovered oEmbed URLs, any non-JSON response or a JSON response which includes non-oEmbed information is discarded. 2. For discovered image URLs, any non-image response is discarded. Systems which have URL preview disabled (via the `url_preview_enabled` setting) or have not configured a `url_preview_url_blacklist` are not affected. This issue has been addressed in version 1.85.0. Users are advised to upgrade. User unable to upgrade may also disable URL previews.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | matrix-synapse | < matrix-synapse 1.90.0-1 (forky) | matrix-synapse 1.90.0-1 (forky) |
| matrix-org | synapse | < 1.85.0 | 1.85.0 |
| matrix | synapse | < 1.85.0 | 1.85.0 |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
osv5.4MEDIUM
vendor_ubuntu5.0MEDIUM
vendor_debian3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Synapse vulnerabilities
vendor_ubuntu·2025-04-22·CVSS 5.0
CVE-2023-41335 [MEDIUM] Synapse vulnerabilities
Title: Synapse vulnerabilities
Summary: Several security issues were fixed in Synapse.
It was discovered that Synapse network policies could be bypassed via
specially crafted URLs. An attacker could possibly use this issue to
bypass authentication mechanisms. (CVE-2023-32683)
It was discovered that Synapse exposed cached device information. An
attacker could possibly use this issue to gain access to sensitive
information. (CVE-2023-43796)
It was discovered that Synapse could be tricked into rejecting state
changes in rooms. An attacker could possibly use this issue to cause
Synapse to stop functioning properly, resulting in a denial of service.
This issue was only fixed in Ubuntu 20.04 LTS and Ubuntu 22.04 LTS.
(CVE-2022-39374)
It was discovered that Synapse stored user credentials in
Debian
CVE-2023-32683: matrix-synapse - Synapse is a Matrix protocol homeserver written in Python with the Twisted frame...
vendor_debian·2023·CVSS 3.5
CVE-2023-32683 [LOW] CVE-2023-32683: matrix-synapse - Synapse is a Matrix protocol homeserver written in Python with the Twisted frame...
Synapse is a Matrix protocol homeserver written in Python with the Twisted framework. A discovered oEmbed or image URL can bypass the `url_preview_url_blacklist` setting potentially allowing server side request forgery or bypassing network policies. Impact is limited to IP addresses allowed by the `url_preview_ip_range_blacklist` setting (by default this only allows public IPs) and by the limited information returned to the client: 1. For discovered oEmbed URLs, any non-JSON response or a JSON response which includes non-oEmbed information is discarded. 2. For discovered image URLs, any non-image response is discarded. Systems which have URL preview disabled (via the `url_preview_enabled` setting) or have not configured a `url_preview_url_blacklist` are not affected. This issue has been ad
OSV
matrix-synapse vulnerabilities
osv·2025-04-22·CVSS 5.0
CVE-2023-32683 [MEDIUM] matrix-synapse vulnerabilities
matrix-synapse vulnerabilities
It was discovered that Synapse network policies could be bypassed via
specially crafted URLs. An attacker could possibly use this issue to
bypass authentication mechanisms. (CVE-2023-32683)
It was discovered that Synapse exposed cached device information. An
attacker could possibly use this issue to gain access to sensitive
information. (CVE-2023-43796)
It was discovered that Synapse could be tricked into rejecting state
changes in rooms. An attacker could possibly use this issue to cause
Synapse to stop functioning properly, resulting in a denial of service.
This issue was only fixed in Ubuntu 20.04 LTS and Ubuntu 22.04 LTS.
(CVE-2022-39374)
It was discovered that Synapse stored user credentials in a server's
database temporarily. An attacker could possi
OSV
CVE-2023-32683: Synapse is a Matrix protocol homeserver written in Python with the Twisted framework
osv·2023-06-06·CVSS 5.4
CVE-2023-32683 [MEDIUM] CVE-2023-32683: Synapse is a Matrix protocol homeserver written in Python with the Twisted framework
Synapse is a Matrix protocol homeserver written in Python with the Twisted framework. A discovered oEmbed or image URL can bypass the `url_preview_url_blacklist` setting potentially allowing server side request forgery or bypassing network policies. Impact is limited to IP addresses allowed by the `url_preview_ip_range_blacklist` setting (by default this only allows public IPs) and by the limited information returned to the client: 1. For discovered oEmbed URLs, any non-JSON response or a JSON response which includes non-oEmbed information is discarded. 2. For discovered image URLs, any non-image response is discarded. Systems which have URL preview disabled (via the `url_preview_enabled` setting) or have not configured a `url_preview_url_blacklist` are not affected. This issue has been ad
OSV
Synapse has URL deny list bypass via oEmbed and image URLs when generating previews
osv·2023-06-06
CVE-2023-32683 [MEDIUM] Synapse has URL deny list bypass via oEmbed and image URLs when generating previews
Synapse has URL deny list bypass via oEmbed and image URLs when generating previews
### Impact
A discovered oEmbed or image URL can bypass the `url_preview_url_blacklist` setting potentially allowing server side request forgery or bypassing network policies. Impact is limited to IP addresses allowed by the `url_preview_ip_range_blacklist` setting (by default this only allows public IPs) and by the limited information returned to the client:
* For discovered oEmbed URLs, any non-JSON response or a JSON response which includes non-oEmbed information is discarded.
* For discovered image URLs, any non-image response is discarded.
Systems which have URL preview disabled (via the `url_preview_enabled` setting) or have not configured a `url_preview_url_blacklist` are not affected.
Because of
GHSA
Synapse has URL deny list bypass via oEmbed and image URLs when generating previews
ghsa·2023-06-06
CVE-2023-32683 [MEDIUM] CWE-863 Synapse has URL deny list bypass via oEmbed and image URLs when generating previews
Synapse has URL deny list bypass via oEmbed and image URLs when generating previews
### Impact
A discovered oEmbed or image URL can bypass the `url_preview_url_blacklist` setting potentially allowing server side request forgery or bypassing network policies. Impact is limited to IP addresses allowed by the `url_preview_ip_range_blacklist` setting (by default this only allows public IPs) and by the limited information returned to the client:
* For discovered oEmbed URLs, any non-JSON response or a JSON response which includes non-oEmbed information is discarded.
* For discovered image URLs, any non-image response is discarded.
Systems which have URL preview disabled (via the `url_preview_enabled` setting) or have not configured a `url_preview_url_blacklist` are not affected.
Because of
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/matrix-org/synapse/pull/15601https://github.com/matrix-org/synapse/security/advisories/GHSA-98px-6486-j7qchttps://lists.fedoraproject.org/archives/list/[email protected]/message/X6DH5A5YEB5LRIPP32OUW25FCGZFCZU2/https://github.com/matrix-org/synapse/pull/15601https://github.com/matrix-org/synapse/security/advisories/GHSA-98px-6486-j7qchttps://lists.fedoraproject.org/archives/list/[email protected]/message/X6DH5A5YEB5LRIPP32OUW25FCGZFCZU2/
2023-06-06
Published