Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2023-41335

Опубликовано: 27 сент. 2023
Источник: ubuntu
Приоритет: medium
CVSS3: 3.7

Описание

Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. When users update their passwords, the new credentials may be briefly held in the server database. While this doesn't grant the server any added capabilities—it already learns the users' passwords as part of the authentication process—it does disrupt the expectation that passwords won't be stored in the database. As a result, these passwords could inadvertently be captured in database backups for a longer duration. These temporarily stored passwords are automatically erased after a 48-hour window. This issue has been addressed in version 1.93.0. Users are advised to upgrade. There are no known workarounds for this issue.

РелизСтатусПримечание
bionic

ignored

end of standard support
esm-apps/bionic

not-affected

code not present
esm-apps/focal

not-affected

code not present
esm-apps/jammy

released

1.53.0-1ubuntu0.1~esm2
esm-apps/noble

not-affected

1.100.0-1ubuntu1
focal

not-affected

code not present
jammy

needed

lunar

ignored

end of life, was needs-triage
mantic

ignored

end of life, was needs-triage
noble

not-affected

1.100.0-1ubuntu1

Показывать по

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 3.7
nvd
больше 2 лет назад

Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. When users update their passwords, the new credentials may be briefly held in the server database. While this doesn't grant the server any added capabilities—it already learns the users' passwords as part of the authentication process—it does disrupt the expectation that passwords won't be stored in the database. As a result, these passwords could inadvertently be captured in database backups for a longer duration. These temporarily stored passwords are automatically erased after a 48-hour window. This issue has been addressed in version 1.93.0. Users are advised to upgrade. There are no known workarounds for this issue.

CVSS3: 3.7
debian
больше 2 лет назад

Synapse is an open-source Matrix homeserver written and maintained by ...

CVSS3: 3.7
github
больше 2 лет назад

matrix-synapse vulnerable to temporary storage of plaintext passwords during password changes

3.7 Low

CVSS3