Search CVE reports


Toggle filters

11 – 20 of 41 results


CVE-2023-42453

Medium priority

Some fixes available 1 of 5

Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. Users were able to forge read receipts for any event (if they knew the room ID and event ID). Note that the users were not able to...

1 affected package

matrix-synapse

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
matrix-synapse Not affected Fixed Ignored Ignored
Show less packages

CVE-2023-41335

Medium priority

Some fixes available 1 of 3

Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. When users update their passwords, the new credentials may be briefly held in the server database. While this doesn't grant the...

1 affected package

matrix-synapse

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
matrix-synapse Not affected Fixed Not affected Not affected
Show less packages

CVE-2023-32683

Medium priority

Some fixes available 3 of 6

Synapse is a Matrix protocol homeserver written in Python with the Twisted framework. A discovered oEmbed or image URL can bypass the `url_preview_url_blacklist` setting potentially allowing server side request forgery or...

1 affected package

matrix-synapse

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
matrix-synapse Not affected Fixed Fixed Fixed
Show less packages

CVE-2023-32682

Medium priority
Ignored

Synapse is a Matrix protocol homeserver written in Python with the Twisted framework. In affected versions it may be possible for a deactivated user to login when using uncommon configurations. This only applies if any of the...

1 affected package

matrix-synapse

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
matrix-synapse Not affected Ignored Ignored Ignored
Show less packages

CVE-2023-32323

Medium priority
Ignored

Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. A malicious user on a Synapse homeserver X with permission to create certain state events can disable outbound federation from X to...

1 affected package

matrix-synapse

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
matrix-synapse Not affected Ignored Ignored Ignored
Show less packages

CVE-2022-41952

Medium priority
Needs evaluation

Synapse before 1.52.0 with URL preview functionality enabled will attempt to generate URL previews for media stream URLs without properly limiting connection time. Connections will only be terminated after `max_spider_size`...

1 affected package

matrix-synapse

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
matrix-synapse Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2022-39374

Medium priority

Some fixes available 2 of 5

Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. If Synapse and a malicious homeserver are both joined to the same room, the malicious homeserver can trick Synapse into accepting...

1 affected package

matrix-synapse

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
matrix-synapse Not affected Fixed Fixed Not affected
Show less packages

CVE-2022-39335

Medium priority

Some fixes available 1 of 6

Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. The Matrix Federation API allows remote homeservers to request the authorization events in a room. This is necessary so that...

1 affected package

matrix-synapse

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
matrix-synapse Not affected Fixed Ignored Ignored
Show less packages

CVE-2022-31152

Medium priority
Needs evaluation

Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. The Matrix specification specifies a list of [event authorization rules](https://spec.matrix.org/v1.2/rooms/v9/#authorization-rules)...

1 affected package

matrix-synapse

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
matrix-synapse Not affected Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-31052

Medium priority
Needs evaluation

Synapse is an open source home server implementation for the Matrix chat network. In versions prior to 1.61.1 URL previews of some web pages can exhaust the available stack space for the Synapse process due to unbounded recursion....

1 affected package

matrix-synapse

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
matrix-synapse Not affected Needs evaluation Needs evaluation Needs evaluation
Show less packages