VDB

CVE-2023-32323

CVE-2023-32323 PUBLISHED CVSS 5 MEDIUM

Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. A malicious user on a Synapse homeserver X with permission to create certain state events can disable outbound federation from X to an arbitrary homeserver Y. Synapse instances with federation disabled are not affected. In versions of Synapse up to and including 1.73, Synapse did not limit the size of `invite_room_state`, meaning that it was possible to create an arbitrarily large invite event. Synapse 1.74 refuses to create oversized `invite_room_state` fields. Server operators should upgrade to Synapse 1.74 or newer urgently.

EPSS 0.14% · 33.1th percentile

Risk Scores

CVSS v3.1
5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L
EPSS Score
0.14%
33.1th percentile

Affected Products

VendorProductVersions
PyPImatrix-synapse0, 0
matrix-orgsynapse*, < 1.74.0
matrixsynapse0, 0

Timeline

  • Dec 13, 2022 Fix PR Merged
  • May 24, 2023 CVE Published
  • May 27, 2023 EPSS Score
  • Jul 2, 2023 EPSS Score
  • Aug 7, 2023 EPSS Score
  • Sep 12, 2023 EPSS Score
  • Oct 18, 2023 EPSS Score
  • Nov 24, 2023 EPSS Score
  • Dec 30, 2023 EPSS Score
  • Feb 4, 2024 EPSS Score
  • Apr 16, 2024 EPSS Score
  • May 22, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›