matrix-synapse@1.119.0 vulnerabilities

Homeserver for the Matrix decentralised comms protocol

  • latest version

    1.128.0

  • latest non vulnerable version

  • first published

    6 years ago

  • latest version published

    11 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the matrix-synapse package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Improper Input Validation

    matrix-synapse is an ecosystem for open federated Instant Messaging and VoIP.

    Affected versions of this package are vulnerable to Improper Input Validation. A malicious server can disrupt the normal operation and prevent the application from federating with other servers by crafting events that exploit this flaw.

    Note:

    This is only exploitable in environments where federation is enabled.

    How to fix Improper Input Validation?

    Upgrade matrix-synapse to version 1.127.1 or higher.

    [,1.127.1)
    • H
    Improper Input Validation

    matrix-synapse is an ecosystem for open federated Instant Messaging and VoIP.

    Affected versions of this package are vulnerable to Improper Input Validation via invite messages. An attacker can disrupt the /sync functionality by sending a specially crafted invite over federation.

    How to fix Improper Input Validation?

    Upgrade matrix-synapse to version 1.120.2 or higher.

    [,1.120.2)
    • M
    Exposure of Sensitive System Information to an Unauthorized Control Sphere

    matrix-synapse is an ecosystem for open federated Instant Messaging and VoIP.

    Affected versions of this package are vulnerable to Exposure of Sensitive System Information to an Unauthorized Control Sphere via the Sliding Sync feature. An attacker can leak partial room state changes to users no longer in a room by exploiting this feature.

    How to fix Exposure of Sensitive System Information to an Unauthorized Control Sphere?

    Upgrade matrix-synapse to version 1.120.2 or higher.

    [1.113.0rc1,1.120.2)
    • H
    Arbitrary File Upload

    matrix-synapse is an ecosystem for open federated Instant Messaging and VoIP.

    Affected versions of this package are vulnerable to Arbitrary File Upload due to the dynamic_thumbnails option or processing a specially crafted request. An attacker can exploit this to execute arbitrary code or cause a denial of service by invoking external, potentially untrustworthy decoders.

    How to fix Arbitrary File Upload?

    Upgrade matrix-synapse to version 1.120.2 or higher.

    [,1.120.2)
    • H
    Allocation of Resources Without Limits or Throttling

    matrix-synapse is an ecosystem for open federated Instant Messaging and VoIP.

    Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling due to the improper handling of multipart/form-data content types. An attacker can amplify denial of service attacks by sending crafted requests that transiently increase memory consumption.

    How to fix Allocation of Resources Without Limits or Throttling?

    Upgrade matrix-synapse to version 1.120.2 or higher.

    [,1.120.2)