Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5chr-wjw5-3gq4

Опубликовано: 10 окт. 2023
Источник: github
Github: Прошло ревью
CVSS4: 6.9
CVSS3: 4.9

Описание

matrix-synapse vulnerable to denial of service due to malicious server ACL events

Impact

A malicious server ACL event can impact performance temporarily or permanently leading to a persistent denial of service.

Homeservers running on a closed federation (which presumably do not need to use server ACLs) are not affected.

Patches

Server administrators are advised to upgrade to Synapse 1.94.0 or later.

Workarounds

Rooms with malicious server ACL events can be purged and blocked using the admin API.

Пакеты

Наименование

matrix-synapse

pip
Затронутые версииВерсия исправления

< 1.94.0

1.94.0

EPSS

Процентиль: 47%
0.00243
Низкий

6.9 Medium

CVSS4

4.9 Medium

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 4.9
ubuntu
больше 2 лет назад

Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. Prior to version 1.94.0, a malicious server ACL event can impact performance temporarily or permanently leading to a persistent denial of service. Homeservers running on a closed federation (which presumably do not need to use server ACLs) are not affected. Server administrators are advised to upgrade to Synapse 1.94.0 or later. As a workaround, rooms with malicious server ACL events can be purged and blocked using the admin API.

CVSS3: 4.9
redhat
больше 2 лет назад

Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. Prior to version 1.94.0, a malicious server ACL event can impact performance temporarily or permanently leading to a persistent denial of service. Homeservers running on a closed federation (which presumably do not need to use server ACLs) are not affected. Server administrators are advised to upgrade to Synapse 1.94.0 or later. As a workaround, rooms with malicious server ACL events can be purged and blocked using the admin API.

CVSS3: 4.9
nvd
больше 2 лет назад

Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. Prior to version 1.94.0, a malicious server ACL event can impact performance temporarily or permanently leading to a persistent denial of service. Homeservers running on a closed federation (which presumably do not need to use server ACLs) are not affected. Server administrators are advised to upgrade to Synapse 1.94.0 or later. As a workaround, rooms with malicious server ACL events can be purged and blocked using the admin API.

CVSS3: 4.9
debian
больше 2 лет назад

Synapse is an open-source Matrix homeserver written and maintained by ...

CVSS3: 4.9
fstec
больше 2 лет назад

Уязвимость механизма управления доступа Access Control List (ACL) домашнего сервера Synapse, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 47%
0.00243
Низкий

6.9 Medium

CVSS4

4.9 Medium

CVSS3

Дефекты

CWE-770