Matrix-Org Synapse vulnerabilities
24 known vulnerabilities affecting matrix-org/synapse.
Total CVEs
24
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM18LOW3
Vulnerabilities
Page 2 of 2
CVE-2021-21333MEDIUMCVSS 6.1fixed in 1.27.02021-03-26
CVE-2021-21333 [MEDIUM] CWE-74 CVE-2021-21333: Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is
Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.27.0, the notification emails sent for notifications for missed messages or for an expiring account are subject to HTML injection. In the case of the notification fo
cvelistv5nvd
CVE-2021-21274MEDIUMCVSS 6.5v>=0.99.0, < 1.25.02021-02-26
CVE-2021-21274 [MEDIUM] CWE-400 CVE-2021-21274: Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is
Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.25.0, a malicious homeserver could redirect requests to their .well-known file to a large file. This can lead to a denial of service attack where homeservers will c
cvelistv5nvd
CVE-2021-21273MEDIUMCVSS 6.1fixed in 1.25.02021-02-26
CVE-2021-21273 [MEDIUM] CWE-601 CVE-2021-21273: Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is
Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.25.0, requests to user provided domains were not restricted to external IP addresses when calculating the key validity for third-party invite events and sending pus
cvelistv5nvd
CVE-2020-26257MEDIUMCVSS 6.5fixed in 1.23.12020-12-09
CVE-2020-26257 [MEDIUM] CWE-79 CVE-2020-26257: Matrix is an ecosystem for open federated Instant Messaging and VoIP. Synapse is a reference "homese
Matrix is an ecosystem for open federated Instant Messaging and VoIP. Synapse is a reference "homeserver" implementation of Matrix. A malicious or poorly-implemented homeserver can inject malformed events into a room by specifying a different room id in the path of a `/send_join`, `/send_leave`, `/invite` or `/exchange_third_party_invite` request. Th
cvelistv5nvd
← Previous2 / 2