Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-39374

Опубликовано: 26 мая 2023
Источник: nvd
CVSS3: 6.5
CVSS3: 6.5
EPSS Низкий

Описание

Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. If Synapse and a malicious homeserver are both joined to the same room, the malicious homeserver can trick Synapse into accepting previously rejected events into its view of the current state of that room. This can be exploited in a way that causes all further messages and state changes sent in that room from the vulnerable homeserver to be rejected. This issue has been patched in version 1.68.0

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:matrix:synapse:*:*:*:*:*:*:*:*
Версия от 1.62.0 (включая) до 1.68.0 (исключая)

EPSS

Процентиль: 37%
0.0016
Низкий

6.5 Medium

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-400
CWE-400

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 2 лет назад

Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. If Synapse and a malicious homeserver are both joined to the same room, the malicious homeserver can trick Synapse into accepting previously rejected events into its view of the current state of that room. This can be exploited in a way that causes all further messages and state changes sent in that room from the vulnerable homeserver to be rejected. This issue has been patched in version 1.68.0

CVSS3: 6.5
debian
больше 2 лет назад

Synapse is an open-source Matrix homeserver written and maintained by ...

CVSS3: 6.5
github
больше 2 лет назад

Synapse Denial of service due to incorrect application of event authorization rules during state resolution

EPSS

Процентиль: 37%
0.0016
Низкий

6.5 Medium

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-400
CWE-400