Vulnerability Description
Synapse is an open-source Matrix homeserver. Synapse versions before 1.120.1 fail to properly validate invites received over federation. This vulnerability allows a malicious server to send a specially crafted invite that disrupts the invited user's /sync functionality. Synapse 1.120.1 rejects such invalid invites received over federation and restores the ability to sync for affected users.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Matrix | Synapse | < 1.120.1 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2024-52815?
CVE-2024-52815 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Synapse is an open-source Matrix homeserver. Synapse versions before 1.120.1 fail to properly validate invites received over federation. This vulnerability allows a malicious server to send a speciall...
How severe is CVE-2024-52815?
CVE-2024-52815 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-52815?
Check the references section above for vendor advisories and patch information. Affected products include: Matrix Synapse.