CVE-2023-45129
published 2023-10-10CVE-2023-45129: Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. Prior to version 1.94.0, a malicious server ACL event can…
PriorityP424medium4.9CVSS 3.1
AVNACLPRHUINSUCNINAH
EPSS
1.17%
63.9th percentile
Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. Prior to version 1.94.0, a malicious server ACL event can impact performance temporarily or permanently leading to a persistent denial of service. Homeservers running on a closed federation (which presumably do not need to use server ACLs) are not affected. Server administrators are advised to upgrade to Synapse 1.94.0 or later. As a workaround, rooms with malicious server ACL events can be purged and blocked using the admin API.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | matrix-synapse | < matrix-synapse 1.94.0-1 (forky) | matrix-synapse 1.94.0-1 (forky) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| matrix-org | synapse | < 1.94.0 | 1.94.0 |
| matrix | synapse | < 1.94.0 | 1.94.0 |
CVSS provenance
nvdv3.14.9MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
osv4.9MEDIUM
vendor_debian4.9MEDIUM
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
synapse: malicious ACL event can cause denial of service
vendor_redhat·2023-10-10·CVSS 4.9
CVE-2023-45129 [MEDIUM] CWE-770 synapse: malicious ACL event can cause denial of service
synapse: malicious ACL event can cause denial of service
Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. Prior to version 1.94.0, a malicious server ACL event can impact performance temporarily or permanently leading to a persistent denial of service. Homeservers running on a closed federation (which presumably do not need to use server ACLs) are not affected. Server administrators are advised to upgrade to Synapse 1.94.0 or later. As a workaround, rooms with malicious server ACL events can be purged and blocked using the admin API.
Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. Prior to version 1.94.0, a malicious server ACL event can impact performance temporarily or permanently leading t
Debian
CVE-2023-45129: matrix-synapse - Synapse is an open-source Matrix homeserver written and maintained by the Matrix...
vendor_debian·2023·CVSS 4.9
CVE-2023-45129 [MEDIUM] CVE-2023-45129: matrix-synapse - Synapse is an open-source Matrix homeserver written and maintained by the Matrix...
Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. Prior to version 1.94.0, a malicious server ACL event can impact performance temporarily or permanently leading to a persistent denial of service. Homeservers running on a closed federation (which presumably do not need to use server ACLs) are not affected. Server administrators are advised to upgrade to Synapse 1.94.0 or later. As a workaround, rooms with malicious server ACL events can be purged and blocked using the admin API.
Scope: local
forky: resolved (fixed in 1.94.0-1)
sid: resolved (fixed in 1.94.0-1)
OSV
CVE-2023-45129: Synapse is an open-source Matrix homeserver written and maintained by the Matrix
osv·2023-10-10·CVSS 4.9
CVE-2023-45129 [MEDIUM] CVE-2023-45129: Synapse is an open-source Matrix homeserver written and maintained by the Matrix
Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. Prior to version 1.94.0, a malicious server ACL event can impact performance temporarily or permanently leading to a persistent denial of service. Homeservers running on a closed federation (which presumably do not need to use server ACLs) are not affected. Server administrators are advised to upgrade to Synapse 1.94.0 or later. As a workaround, rooms with malicious server ACL events can be purged and blocked using the admin API.
OSV
matrix-synapse vulnerable to denial of service due to malicious server ACL events
osv·2023-10-10
CVE-2023-45129 [MEDIUM] matrix-synapse vulnerable to denial of service due to malicious server ACL events
matrix-synapse vulnerable to denial of service due to malicious server ACL events
### Impact
A malicious server ACL event can impact performance temporarily or permanently leading to a persistent denial of service.
Homeservers running on a closed federation (which presumably do not need to use server ACLs) are not affected.
### Patches
Server administrators are advised to upgrade to Synapse 1.94.0 or later.
### Workarounds
Rooms with malicious server ACL events can be [purged and blocked](https://matrix-org.github.io/synapse/latest/admin_api/rooms.html#version-2-new-version) using the admin API.
GHSA
matrix-synapse vulnerable to denial of service due to malicious server ACL events
ghsa·2023-10-10
CVE-2023-45129 [MEDIUM] CWE-770 matrix-synapse vulnerable to denial of service due to malicious server ACL events
matrix-synapse vulnerable to denial of service due to malicious server ACL events
### Impact
A malicious server ACL event can impact performance temporarily or permanently leading to a persistent denial of service.
Homeservers running on a closed federation (which presumably do not need to use server ACLs) are not affected.
### Patches
Server administrators are advised to upgrade to Synapse 1.94.0 or later.
### Workarounds
Rooms with malicious server ACL events can be [purged and blocked](https://matrix-org.github.io/synapse/latest/admin_api/rooms.html#version-2-new-version) using the admin API.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/matrix-org/synapse/pull/16360https://github.com/matrix-org/synapse/security/advisories/GHSA-5chr-wjw5-3gq4https://lists.fedoraproject.org/archives/list/[email protected]/message/KEVRB4MG5UXQ5RLZHSUJXM5GWEBYYS5B/https://lists.fedoraproject.org/archives/list/[email protected]/message/N6P4QULVUE254WI7XF2LWWOGHCYVFXFY/https://lists.fedoraproject.org/archives/list/[email protected]/message/WRO4MPQ6HOXIUZM6RJP6VTCTMV7RD2T3/https://matrix-org.github.io/synapse/latest/admin_api/rooms.html#version-2-new-versionhttps://security.gentoo.org/glsa/202401-12https://github.com/matrix-org/synapse/pull/16360https://github.com/matrix-org/synapse/security/advisories/GHSA-5chr-wjw5-3gq4https://lists.fedoraproject.org/archives/list/[email protected]/message/KEVRB4MG5UXQ5RLZHSUJXM5GWEBYYS5B/https://lists.fedoraproject.org/archives/list/[email protected]/message/N6P4QULVUE254WI7XF2LWWOGHCYVFXFY/https://lists.fedoraproject.org/archives/list/[email protected]/message/WRO4MPQ6HOXIUZM6RJP6VTCTMV7RD2T3/https://matrix-org.github.io/synapse/latest/admin_api/rooms.html#version-2-new-versionhttps://security.gentoo.org/glsa/202401-12
2023-10-10
Published