cbcvebase.

Matrix-Org Synapse vulnerabilities

24 known vulnerabilities affecting matrix-org/synapse.

Total CVEs
24
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM18LOW3

Vulnerabilities

Page 2 of 2
CVE-2023-42453P4MEDIUMCVSS 4.3v>= 0.34.0, < 1.93.02023-09-27
CVE-2023-42453 [MEDIUM] CWE-285 CVE-2023-42453: Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. Use Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. Users were able to forge read receipts for any event (if they knew the room ID and event ID). Note that the users were not able to view the events, but simply mark it as read. This could be confusing as clients will show the event as read by the user, ev
nvd
CVE-2023-41335P4LOWCVSS 3.7v>= 1.66.0, < 1.93.02023-09-27
CVE-2023-41335 [LOW] CWE-312 CVE-2023-41335: Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. Whe Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. When users update their passwords, the new credentials may be briefly held in the server database. While this doesn't grant the server any added capabilities—it already learns the users' passwords as part of the authentication process—it does disrupt the ex
nvd
CVE-2021-39164P4LOWCVSS 3.1fixed in 1.41.12021-08-31
CVE-2021-39164 [LOW] CWE-200 CVE-2021-39164: Matrix is an ecosystem for open federated Instant Messaging and Voice over IP. In versions 1.41.0 an Matrix is an ecosystem for open federated Instant Messaging and Voice over IP. In versions 1.41.0 and prior, unauthorised users can access the membership (list of members, with their display names) of a room if they know the ID of the room. The vulnerability is limited to rooms with `shared` history visibility. Furthermore, the unauthorised user must b
nvd
CVE-2021-39163P4LOWCVSS 3.1fixed in 1.41.12021-08-31
CVE-2021-39163 [LOW] CWE-200 CVE-2021-39163: Matrix is an ecosystem for open federated Instant Messaging and Voice over IP. In versions 1.41.0 an Matrix is an ecosystem for open federated Instant Messaging and Voice over IP. In versions 1.41.0 and prior, unauthorised users can access the name, avatar, topic and number of members of a room if they know the ID of the room. This vulnerability is limited to homeservers where the vulnerable homeserver is in the room and untrusted users are permitted
nvd