PyPi: Matrix-Synapse

CVE-2024-52815

Safety vulnerability ID: 74423

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at Dec 03, 2024 Updated at Dec 11, 2024
Scan your Python projects for vulnerabilities →

Advisory

Affected versions of Synapse are vulnerable to improper input validation (CWE-20). This flaw allows a malicious server to send specially crafted invites over federation, disrupting the invited user's /sync functionality. The vulnerability can be exploited remotely via federation invites targeting the invite handling methods. To mitigate, update to Synapse version 1.120.1, which rejects invalid invites and restores sync functionality. As a workaround, server administrators can disable federation from untrusted servers.

Affected package

matrix-synapse

Latest version: 1.121.1

Homeserver for the Matrix decentralised comms protocol

Affected versions

Fixed versions

Vulnerability changelog

This vulnerability has no description

Resources

Use this package?

Scan your Python project for dependency vulnerabilities in two minutes

Scan your application