CVE-2024-52815Improper Input Validation in Synapse

Severity
8.7HIGHNVD
EPSS
0.3%
top 51.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 3

Description

Synapse is an open-source Matrix homeserver. Synapse versions before 1.120.1 fail to properly validate invites received over federation. This vulnerability allows a malicious server to send a specially crafted invite that disrupts the invited user's /sync functionality. Synapse 1.120.1 rejects such invalid invites received over federation and restores the ability to sync for affected users.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Packages2 packages

NVDmatrix/synapse< 1.120.1
CVEListV5element-hq/synapse< 1.120.1

🔴Vulnerability Details

4
GHSA
Synapse allows a a malformed invite to break the invitee's `/sync`2024-12-03
CVEList
Synapse allows a a malformed invite to break the invitee's `/sync`2024-12-03
OSV
CVE-2024-52815: Synapse is an open-source Matrix homeserver2024-12-03
OSV
Synapse allows a a malformed invite to break the invitee's `/sync`2024-12-03

📋Vendor Advisories

1
Debian
CVE-2024-52815: matrix-synapse - Synapse is an open-source Matrix homeserver. Synapse versions before 1.120.1 fai...2024
CVE-2024-52815 — Improper Input Validation in Synapse | cvebase