Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-52815

Опубликовано: 03 дек. 2024
Источник: ubuntu
Приоритет: medium
CVSS3: 5.3

Описание

Synapse is an open-source Matrix homeserver. Synapse versions before 1.120.1 fail to properly validate invites received over federation. This vulnerability allows a malicious server to send a specially crafted invite that disrupts the invited user's /sync functionality. Synapse 1.120.1 rejects such invalid invites received over federation and restores the ability to sync for affected users.

РелизСтатусПримечание
esm-apps/bionic

deferred

7/4/2025
esm-apps/focal

deferred

7/4/2025
esm-apps/jammy

deferred

7/4/2025
esm-apps/noble

deferred

7/4/2025
focal

ignored

end of standard support, was deferred [7/4/2025]
jammy

deferred

7/4/2025
noble

deferred

7/4/2025
oracular

ignored

end of life, was deferred [7/4/2025]
upstream

released

1.120.1

Показывать по

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
около 1 года назад

Synapse is an open-source Matrix homeserver. Synapse versions before 1.120.1 fail to properly validate invites received over federation. This vulnerability allows a malicious server to send a specially crafted invite that disrupts the invited user's /sync functionality. Synapse 1.120.1 rejects such invalid invites received over federation and restores the ability to sync for affected users.

CVSS3: 5.3
debian
около 1 года назад

Synapse is an open-source Matrix homeserver. Synapse versions before 1 ...

github
около 1 года назад

Synapse allows a a malformed invite to break the invitee's `/sync`

5.3 Medium

CVSS3