CVE-2023-45129Medium· 4.9▾ Sunlitmatrix-synapse vulnerable to denial of service due to malicious server ACL events
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
1.2%
A malicious server ACL event can impact performance temporarily or permanently leading to a persistent denial of service.
Homeservers running on a closed federation (which presumably do not need to use server ACLs) are not affected.
Server administrators are advised to upgrade to Synapse 1.94.0 or later.
Rooms with malicious server ACL events can be purged and blocked using the admin API.
matrix-synapse < 1.94.0Upgrade to a patched release:
matrix-synapse 1.94.0Connected by shared product, vendor, weakness, or advisory.
CVE-2023-42453Low· 3.1matrix-synapse vulnerable to improper validation of receipts allows forged read receipts
CVE-2023-41335Low· 3.7matrix-synapse vulnerable to temporary storage of plaintext passwords during password changes
CVE-2023-43796Medium· 5.3Synapse vulnerable to leak of remote user device information
CVE-2021-21274Medium· 4.3Denial of service attack via .well-known lookups
CVE-2023-32682Medium· 5.4Synapse has improper checks for deactivated users during login
CVE-2021-29471Low· 3.7Denial of service attack via push rule patterns in matrix-synapse