VDB

CVE-2022-39335

CVE-2022-39335 PUBLISHED CVSS 5 MEDIUM

Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. The Matrix Federation API allows remote homeservers to request the authorization events in a room. This is necessary so that a homeserver receiving some events can validate that those events are legitimate and permitted in their room. However, in versions of Synapse up to and including 1.68.0, a Synapse homeserver answering a query for authorization events does not sufficiently check that the requesting server should be able to access them. The issue was patched in Synapse 1.69.0. Homeserver administrators are advised to upgrade.

EPSS 0.14% · 33.4th percentile

Risk Scores

CVSS v3.1
5
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
EPSS Score
0.14%
33.4th percentile

Affected Products

VendorProductVersions
matrixsynapse0
PyPImatrix-synapse0
matrix-orgsynapse*

Timeline

  • May 24, 2023 CVE Published
  • May 27, 2023 EPSS Score
  • Jul 2, 2023 EPSS Score
  • Aug 7, 2023 EPSS Score
  • Sep 12, 2023 EPSS Score
  • Oct 18, 2023 EPSS Score
  • Nov 24, 2023 EPSS Score
  • Dec 30, 2023 EPSS Score
  • Feb 4, 2024 EPSS Score
  • Mar 11, 2024 EPSS Score
  • Apr 16, 2024 EPSS Score
  • May 22, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›