CVE-2024-52815
published 2024-12-03CVE-2024-52815: Synapse is an open-source Matrix homeserver. Synapse versions before 1.120.1 fail to properly validate invites received over federation. This vulnerability…
PriorityP428medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
0.55%
42.3th percentile
Synapse is an open-source Matrix homeserver. Synapse versions before 1.120.1 fail to properly validate invites received over federation. This vulnerability allows a malicious server to send a specially crafted invite that disrupts the invited user's /sync functionality. Synapse 1.120.1 rejects such invalid invites received over federation and restores the ability to sync for affected users.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | matrix-synapse | < matrix-synapse 1.121.0-1 (forky) | matrix-synapse 1.121.0-1 (forky) |
| element-hq | synapse | < 1.120.1 | 1.120.1 |
| matrix | synapse | < 1.120.1 | 1.120.1 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv8.7HIGH
vendor_debian8.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2024-52815: matrix-synapse - Synapse is an open-source Matrix homeserver. Synapse versions before 1.120.1 fai...
vendor_debian·2024·CVSS 8.7
CVE-2024-52815 [HIGH] CVE-2024-52815: matrix-synapse - Synapse is an open-source Matrix homeserver. Synapse versions before 1.120.1 fai...
Synapse is an open-source Matrix homeserver. Synapse versions before 1.120.1 fail to properly validate invites received over federation. This vulnerability allows a malicious server to send a specially crafted invite that disrupts the invited user's /sync functionality. Synapse 1.120.1 rejects such invalid invites received over federation and restores the ability to sync for affected users.
Scope: local
forky: resolved (fixed in 1.121.0-1)
sid: resolved (fixed in 1.121.0-1)
GHSA
Synapse allows a a malformed invite to break the invitee's `/sync`
ghsa·2024-12-03
CVE-2024-52815 [HIGH] CWE-20 Synapse allows a a malformed invite to break the invitee's `/sync`
Synapse allows a a malformed invite to break the invitee's `/sync`
### Impact
Synapse versions before 1.120.1 fail to properly validate invites received over federation. This vulnerability allows a malicious server to send a specially crafted invite that disrupts the invited user's `/sync` functionality.
### Patches
Synapse 1.120.1 rejects such invalid invites received over federation and restores the ability to sync for affected users.
### Workarounds
Server administrators can disable federation from untrusted servers.
### For more information
If you have any questions or comments about this advisory, please email us at [security at element.io](mailto:[email protected]).
OSV
CVE-2024-52815: Synapse is an open-source Matrix homeserver
osv·2024-12-03·CVSS 8.7
CVE-2024-52815 [HIGH] CVE-2024-52815: Synapse is an open-source Matrix homeserver
Synapse is an open-source Matrix homeserver. Synapse versions before 1.120.1 fail to properly validate invites received over federation. This vulnerability allows a malicious server to send a specially crafted invite that disrupts the invited user's /sync functionality. Synapse 1.120.1 rejects such invalid invites received over federation and restores the ability to sync for affected users.
OSV
Synapse allows a a malformed invite to break the invitee's `/sync`
osv·2024-12-03
CVE-2024-52815 [HIGH] Synapse allows a a malformed invite to break the invitee's `/sync`
Synapse allows a a malformed invite to break the invitee's `/sync`
### Impact
Synapse versions before 1.120.1 fail to properly validate invites received over federation. This vulnerability allows a malicious server to send a specially crafted invite that disrupts the invited user's `/sync` functionality.
### Patches
Synapse 1.120.1 rejects such invalid invites received over federation and restores the ability to sync for affected users.
### Workarounds
Server administrators can disable federation from untrusted servers.
### For more information
If you have any questions or comments about this advisory, please email us at [security at element.io](mailto:[email protected]).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-12-03
Published