Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-39374

Опубликовано: 26 мая 2023
Источник: ubuntu
Приоритет: medium
CVSS3: 6.5

Описание

Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. If Synapse and a malicious homeserver are both joined to the same room, the malicious homeserver can trick Synapse into accepting previously rejected events into its view of the current state of that room. This can be exploited in a way that causes all further messages and state changes sent in that room from the vulnerable homeserver to be rejected. This issue has been patched in version 1.68.0

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
esm-apps/bionic

not-affected

code not present
esm-apps/focal

released

1.11.0-1ubuntu0.1~esm2
esm-apps/jammy

released

1.53.0-1ubuntu0.1~esm2
esm-apps/noble

not-affected

1.100.0-1ubuntu1
focal

ignored

end of standard support, was needed
jammy

needed

kinetic

ignored

end of life, was needs-triage
lunar

ignored

end of life, was needs-triage
mantic

ignored

end of life, was needs-triage

Показывать по

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
больше 2 лет назад

Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. If Synapse and a malicious homeserver are both joined to the same room, the malicious homeserver can trick Synapse into accepting previously rejected events into its view of the current state of that room. This can be exploited in a way that causes all further messages and state changes sent in that room from the vulnerable homeserver to be rejected. This issue has been patched in version 1.68.0

CVSS3: 6.5
debian
больше 2 лет назад

Synapse is an open-source Matrix homeserver written and maintained by ...

CVSS3: 6.5
github
больше 2 лет назад

Synapse Denial of service due to incorrect application of event authorization rules during state resolution

6.5 Medium

CVSS3