CVE-2023-43796
published 2023-10-31CVE-2023-43796: Synapse is an open-source Matrix homeserver Prior to versions 1.95.1 and 1.96.0rc1, cached device information of remote users can be queried from Synapse. This…
PriorityP427medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.90%
55.6th percentile
Synapse is an open-source Matrix homeserver Prior to versions 1.95.1 and 1.96.0rc1, cached device information of remote users can be queried from Synapse. This can be used to enumerate the remote users known to a homeserver. System administrators are encouraged to upgrade to Synapse 1.95.1 or 1.96.0rc1 to receive a patch. As a workaround, the `federation_domain_whitelist` can be used to limit federation traffic with a homeserver.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | matrix-synapse | < matrix-synapse 1.95.1-1 (forky) | matrix-synapse 1.95.1-1 (forky) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| matrix-org | synapse | < 1.95.1 | 1.95.1 |
| matrix | synapse | < 1.95.1 | 1.95.1 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Synapse vulnerabilities
vendor_ubuntu·2025-04-22·CVSS 5.0
CVE-2023-41335 [MEDIUM] Synapse vulnerabilities
Title: Synapse vulnerabilities
Summary: Several security issues were fixed in Synapse.
It was discovered that Synapse network policies could be bypassed via
specially crafted URLs. An attacker could possibly use this issue to
bypass authentication mechanisms. (CVE-2023-32683)
It was discovered that Synapse exposed cached device information. An
attacker could possibly use this issue to gain access to sensitive
information. (CVE-2023-43796)
It was discovered that Synapse could be tricked into rejecting state
changes in rooms. An attacker could possibly use this issue to cause
Synapse to stop functioning properly, resulting in a denial of service.
This issue was only fixed in Ubuntu 20.04 LTS and Ubuntu 22.04 LTS.
(CVE-2022-39374)
It was discovered that Synapse stored user credentials in
Debian
CVE-2023-43796: matrix-synapse - Synapse is an open-source Matrix homeserver Prior to versions 1.95.1 and 1.96.0r...
vendor_debian·2023·CVSS 5.3
CVE-2023-43796 [MEDIUM] CVE-2023-43796: matrix-synapse - Synapse is an open-source Matrix homeserver Prior to versions 1.95.1 and 1.96.0r...
Synapse is an open-source Matrix homeserver Prior to versions 1.95.1 and 1.96.0rc1, cached device information of remote users can be queried from Synapse. This can be used to enumerate the remote users known to a homeserver. System administrators are encouraged to upgrade to Synapse 1.95.1 or 1.96.0rc1 to receive a patch. As a workaround, the `federation_domain_whitelist` can be used to limit federation traffic with a homeserver.
Scope: local
forky: resolved (fixed in 1.95.1-1)
sid: resolved (fixed in 1.95.1-1)
GHSA
Liferay Portal: Missing Rate Limiting in GraphQL Endpoint Enables Resource Exhaustion Attack
ghsa·2025-09-12
CVE-2025-43796 [HIGH] CWE-400 Liferay Portal: Missing Rate Limiting in GraphQL Endpoint Enables Resource Exhaustion Attack
Liferay Portal: Missing Rate Limiting in GraphQL Endpoint Enables Resource Exhaustion Attack
Liferay Portal 7.4.0 through 7.4.3.101, and Liferay DXP 2023.Q3.0 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA though update 35 does not limit the number of objects returned from a GraphQL queries, which allows remote attackers to perform denial-of-service (DoS) attacks on the application by executing queries that return a large number of objects.
OSV
matrix-synapse vulnerabilities
osv·2025-04-22·CVSS 5.0
CVE-2023-32683 [MEDIUM] matrix-synapse vulnerabilities
matrix-synapse vulnerabilities
It was discovered that Synapse network policies could be bypassed via
specially crafted URLs. An attacker could possibly use this issue to
bypass authentication mechanisms. (CVE-2023-32683)
It was discovered that Synapse exposed cached device information. An
attacker could possibly use this issue to gain access to sensitive
information. (CVE-2023-43796)
It was discovered that Synapse could be tricked into rejecting state
changes in rooms. An attacker could possibly use this issue to cause
Synapse to stop functioning properly, resulting in a denial of service.
This issue was only fixed in Ubuntu 20.04 LTS and Ubuntu 22.04 LTS.
(CVE-2022-39374)
It was discovered that Synapse stored user credentials in a server's
database temporarily. An attacker could possi
GHSA
Synapse vulnerable to leak of remote user device information
ghsa·2023-10-31
CVE-2023-43796 [MEDIUM] CWE-200 Synapse vulnerable to leak of remote user device information
Synapse vulnerable to leak of remote user device information
### Impact
Cached device information of remote users can be queried from Synapse. This can be used to enumerate the remote users known to a homeserver.
### Patches
System administrators are encouraged to upgrade to Synapse 1.95.1 as soon as possible.
### Workarounds
The `federation_domain_whitelist` can be used to limit federation traffic with a homeserver.
OSV
Synapse vulnerable to leak of remote user device information
osv·2023-10-31
CVE-2023-43796 [MEDIUM] Synapse vulnerable to leak of remote user device information
Synapse vulnerable to leak of remote user device information
### Impact
Cached device information of remote users can be queried from Synapse. This can be used to enumerate the remote users known to a homeserver.
### Patches
System administrators are encouraged to upgrade to Synapse 1.95.1 as soon as possible.
### Workarounds
The `federation_domain_whitelist` can be used to limit federation traffic with a homeserver.
OSV
CVE-2023-43796: Synapse is an open-source Matrix homeserver Prior to versions 1
osv·2023-10-31·CVSS 5.3
CVE-2023-43796 [MEDIUM] CVE-2023-43796: Synapse is an open-source Matrix homeserver Prior to versions 1
Synapse is an open-source Matrix homeserver Prior to versions 1.95.1 and 1.96.0rc1, cached device information of remote users can be queried from Synapse. This can be used to enumerate the remote users known to a homeserver. System administrators are encouraged to upgrade to Synapse 1.95.1 or 1.96.0rc1 to receive a patch. As a workaround, the `federation_domain_whitelist` can be used to limit federation traffic with a homeserver.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/matrix-org/synapse/commit/daec55e1fe120c564240c5386e77941372bf458fhttps://github.com/matrix-org/synapse/security/advisories/GHSA-mp92-3jfm-3575https://lists.fedoraproject.org/archives/list/[email protected]/message/2IDEEZMFJBDLTFHQUTZRJJNCOZGQ2ZVS/https://lists.fedoraproject.org/archives/list/[email protected]/message/VH3RNC5ZPQZ4OKPSL4E6BBJSZOQLGDEY/https://security.gentoo.org/glsa/202401-12https://github.com/matrix-org/synapse/commit/daec55e1fe120c564240c5386e77941372bf458fhttps://github.com/matrix-org/synapse/security/advisories/GHSA-mp92-3jfm-3575https://lists.fedoraproject.org/archives/list/[email protected]/message/2IDEEZMFJBDLTFHQUTZRJJNCOZGQ2ZVS/https://lists.fedoraproject.org/archives/list/[email protected]/message/VH3RNC5ZPQZ4OKPSL4E6BBJSZOQLGDEY/https://security.gentoo.org/glsa/202401-12
2023-10-31
Published