Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-39374

Опубликовано: 26 мая 2023
Источник: debian
EPSS Низкий

Описание

Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. If Synapse and a malicious homeserver are both joined to the same room, the malicious homeserver can trick Synapse into accepting previously rejected events into its view of the current state of that room. This can be exploited in a way that causes all further messages and state changes sent in that room from the vulnerable homeserver to be rejected. This issue has been patched in version 1.68.0

Пакеты

ПакетСтатусВерсия исправленияРелизТип
matrix-synapsefixed1.68.0-1package

Примечания

  • https://matrix.org/blog/2023/05/24/disclosing-synapse-security-advisories/

  • https://github.com/matrix-org/synapse/security/advisories/GHSA-p9qp-c452-f9r7

  • https://bugzilla.redhat.com/show_bug.cgi?id=2209956

EPSS

Процентиль: 37%
0.0016
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 2 лет назад

Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. If Synapse and a malicious homeserver are both joined to the same room, the malicious homeserver can trick Synapse into accepting previously rejected events into its view of the current state of that room. This can be exploited in a way that causes all further messages and state changes sent in that room from the vulnerable homeserver to be rejected. This issue has been patched in version 1.68.0

CVSS3: 6.5
nvd
больше 2 лет назад

Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. If Synapse and a malicious homeserver are both joined to the same room, the malicious homeserver can trick Synapse into accepting previously rejected events into its view of the current state of that room. This can be exploited in a way that causes all further messages and state changes sent in that room from the vulnerable homeserver to be rejected. This issue has been patched in version 1.68.0

CVSS3: 6.5
github
больше 2 лет назад

Synapse Denial of service due to incorrect application of event authorization rules during state resolution

EPSS

Процентиль: 37%
0.0016
Низкий