CVE-2024-53867
published 2024-12-03CVE-2024-53867: Synapse is an open-source Matrix homeserver. The Sliding Sync feature on Synapse versions between 1.113.0rc1 and 1.120.0 can leak partial room state changes to…
PriorityP418medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
0.43%
34.7th percentile
Synapse is an open-source Matrix homeserver. The Sliding Sync feature on Synapse versions between 1.113.0rc1 and 1.120.0 can leak partial room state changes to users no longer in a room. Non-state events, like messages, are unaffected. This vulnerability is fixed in 1.120.1.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | matrix-synapse | < matrix-synapse 1.121.0-1 (forky) | matrix-synapse 1.121.0-1 (forky) |
| element-hq | synapse | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2024-53867: Synapse is an open-source Matrix homeserver
osv·2024-12-03·CVSS 4.3
CVE-2024-53867 [MEDIUM] CVE-2024-53867: Synapse is an open-source Matrix homeserver
Synapse is an open-source Matrix homeserver. The Sliding Sync feature on Synapse versions between 1.113.0rc1 and 1.120.0 can leak partial room state changes to users no longer in a room. Non-state events, like messages, are unaffected. This vulnerability is fixed in 1.120.1.
OSV
Synapse Matrix has a partial room state leak via Sliding Sync
osv·2024-12-03
CVE-2024-53867 [MEDIUM] Synapse Matrix has a partial room state leak via Sliding Sync
Synapse Matrix has a partial room state leak via Sliding Sync
### Impact
The Sliding Sync feature on Synapse versions between 1.113.0rc1 and 1.120.0 can leak partial room state changes to users no longer in a room. Non-state events, like messages, are unaffected.
### Patches
Synapse version 1.120.1 fixes the problem.
### Workarounds
Disable Sliding Sync.
### References
https://github.com/matrix-org/matrix-spec-proposals/pull/4186
https://github.com/element-hq/synapse/blob/d80cd57c54427687afcb48740d99219c88a0fff1/synapse/config/experimental.py#L341-L344
### For more information
If you have any questions or comments about this advisory, please email us at [security at element.io](mailto:[email protected]).
GHSA
Synapse Matrix has a partial room state leak via Sliding Sync
ghsa·2024-12-03
CVE-2024-53867 [MEDIUM] CWE-497 Synapse Matrix has a partial room state leak via Sliding Sync
Synapse Matrix has a partial room state leak via Sliding Sync
### Impact
The Sliding Sync feature on Synapse versions between 1.113.0rc1 and 1.120.0 can leak partial room state changes to users no longer in a room. Non-state events, like messages, are unaffected.
### Patches
Synapse version 1.120.1 fixes the problem.
### Workarounds
Disable Sliding Sync.
### References
https://github.com/matrix-org/matrix-spec-proposals/pull/4186
https://github.com/element-hq/synapse/blob/d80cd57c54427687afcb48740d99219c88a0fff1/synapse/config/experimental.py#L341-L344
### For more information
If you have any questions or comments about this advisory, please email us at [security at element.io](mailto:[email protected]).
Debian
CVE-2024-53867: matrix-synapse - Synapse is an open-source Matrix homeserver. The Sliding Sync feature on Synapse...
vendor_debian·2024·CVSS 4.3
CVE-2024-53867 [MEDIUM] CVE-2024-53867: matrix-synapse - Synapse is an open-source Matrix homeserver. The Sliding Sync feature on Synapse...
Synapse is an open-source Matrix homeserver. The Sliding Sync feature on Synapse versions between 1.113.0rc1 and 1.120.0 can leak partial room state changes to users no longer in a room. Non-state events, like messages, are unaffected. This vulnerability is fixed in 1.120.1.
Scope: local
forky: resolved (fixed in 1.121.0-1)
sid: resolved (fixed in 1.121.0-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-12-03
Published