Vulnerability Description
Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. Prior to version 1.94.0, a malicious server ACL event can impact performance temporarily or permanently leading to a persistent denial of service. Homeservers running on a closed federation (which presumably do not need to use server ACLs) are not affected. Server administrators are advised to upgrade to Synapse 1.94.0 or later. As a workaround, rooms with malicious server ACL events can be purged and blocked using the admin API.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Matrix | Synapse | < 1.94.0 |
| Fedoraproject | Fedora | 37 |
Related Weaknesses (CWE)
References
- https://github.com/matrix-org/synapse/pull/16360PatchVendor Advisory
- https://github.com/matrix-org/synapse/security/advisories/GHSA-5chr-wjw5-3gq4Vendor Advisory
- https://lists.fedoraproject.org/archives/list/[email protected]Mailing List
- https://lists.fedoraproject.org/archives/list/[email protected]
- https://lists.fedoraproject.org/archives/list/[email protected]Mailing List
- https://matrix-org.github.io/synapse/latest/admin_api/rooms.html#version-2-new-vRelease Notes
- https://security.gentoo.org/glsa/202401-12
- https://github.com/matrix-org/synapse/pull/16360PatchVendor Advisory
- https://github.com/matrix-org/synapse/security/advisories/GHSA-5chr-wjw5-3gq4Vendor Advisory
- https://lists.fedoraproject.org/archives/list/[email protected]Mailing List
- https://lists.fedoraproject.org/archives/list/[email protected]
- https://lists.fedoraproject.org/archives/list/[email protected]Mailing List
- https://matrix-org.github.io/synapse/latest/admin_api/rooms.html#version-2-new-vRelease Notes
- https://security.gentoo.org/glsa/202401-12
FAQ
What is CVE-2023-45129?
CVE-2023-45129 is a vulnerability with a CVSS score of 4.9 (MEDIUM). Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. Prior to version 1.94.0, a malicious server ACL event can impact performance temporarily or permanently...
How severe is CVE-2023-45129?
CVE-2023-45129 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-45129?
Check the references section above for vendor advisories and patch information. Affected products include: Matrix Synapse, Fedoraproject Fedora.