CVE-2022-39335
Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. The Matrix Federation API allows remote homeservers to request the authorization events in a room. This is necessary so that a homeserver receiving some events can validate that those events are legitimate and permitted in their room. However, in versions of Synapse up to and including 1.68.0, a Synapse homeserver answering a query for authorization events does not sufficiently check that the requesting server should be able to access them. The issue was patched in Synapse 1.69.0. Homeserver administrators are advised to upgrade.
EPSS 0.14% · 33.4th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| matrix | synapse | 0 |
| PyPI | matrix-synapse | 0 |
| matrix-org | synapse | * |
Timeline
- May 24, 2023 CVE Published
- May 27, 2023 EPSS Score
- Jul 2, 2023 EPSS Score
- Aug 7, 2023 EPSS Score
- Sep 12, 2023 EPSS Score
- Oct 18, 2023 EPSS Score
- Nov 24, 2023 EPSS Score
- Dec 30, 2023 EPSS Score
- Feb 4, 2024 EPSS Score
- Mar 11, 2024 EPSS Score
- Apr 16, 2024 EPSS Score
- May 22, 2024 EPSS Score
References
- https://github.com/matrix-org/synapse/security/advisories/GHSA-45cj-f97f-ggwv url
- https://github.com/matrix-org/synapse/issues/13288 url
- https://github.com/matrix-org/synapse/pull/13823 url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T2MBNMZAFY4RCZL2VGBGAPKGB4JUPZVS/ url
- https://nvd.nist.gov/vuln/detail/CVE-2022-39335 advisory
- https://github.com/matrix-org/synapse package
- https://github.com/pypa/advisory-database/tree/main/vulns/matrix-synapse/PYSEC-2023-65.yaml url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T2MBNMZAFY4RCZL2VGBGAPKGB4JUPZVS url