Matrix

Synapse

40 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.11%
  • Veröffentlicht 27.09.2023 15:19:30
  • Zuletzt bearbeitet 21.11.2024 08:21:06

Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. When users update their passwords, the new credentials may be briefly held in the server database. While this doesn't grant the server any added capabili...

  • EPSS 0.25%
  • Veröffentlicht 06.06.2023 19:15:11
  • Zuletzt bearbeitet 21.11.2024 08:03:50

Synapse is a Matrix protocol homeserver written in Python with the Twisted framework. A discovered oEmbed or image URL can bypass the `url_preview_url_blacklist` setting potentially allowing server side request forgery or bypassing network policies. ...

  • EPSS 0.68%
  • Veröffentlicht 06.06.2023 19:15:11
  • Zuletzt bearbeitet 21.11.2024 08:03:50

Synapse is a Matrix protocol homeserver written in Python with the Twisted framework. In affected versions it may be possible for a deactivated user to login when using uncommon configurations. This only applies if any of the following are true: 1. J...

Exploit
  • EPSS 0.13%
  • Veröffentlicht 26.05.2023 14:15:10
  • Zuletzt bearbeitet 13.02.2025 17:16:30

Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. A malicious user on a Synapse homeserver X with permission to create certain state events can disable outbound federation from X to an arbitrary homeserv...

  • EPSS 0.16%
  • Veröffentlicht 26.05.2023 14:15:10
  • Zuletzt bearbeitet 13.02.2025 17:15:42

Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. If Synapse and a malicious homeserver are both joined to the same room, the malicious homeserver can trick Synapse into accepting previously rejected eve...

  • EPSS 0.15%
  • Veröffentlicht 26.05.2023 14:15:09
  • Zuletzt bearbeitet 21.11.2024 07:18:03

Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. The Matrix Federation API allows remote homeservers to request the authorization events in a room. This is necessary so that a homeserver receiving some ...

  • EPSS 0.07%
  • Veröffentlicht 22.11.2022 16:15:10
  • Zuletzt bearbeitet 21.11.2024 07:24:08

Synapse before 1.52.0 with URL preview functionality enabled will attempt to generate URL previews for media stream URLs without properly limiting connection time. Connections will only be terminated after `max_spider_size` (default: 10M) bytes have ...

  • EPSS 0.69%
  • Veröffentlicht 02.09.2022 20:15:08
  • Zuletzt bearbeitet 21.11.2024 07:04:00

Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. The Matrix specification specifies a list of [event authorization rules](https://spec.matrix.org/v1.2/rooms/v9/#authorization-rules) which must be checke...

  • EPSS 0.74%
  • Veröffentlicht 28.06.2022 17:15:08
  • Zuletzt bearbeitet 21.11.2024 07:03:47

Synapse is an open source home server implementation for the Matrix chat network. In versions prior to 1.61.1 URL previews of some web pages can exhaust the available stack space for the Synapse process due to unbounded recursion. This is sometimes r...

  • EPSS 0.55%
  • Veröffentlicht 23.11.2021 20:15:11
  • Zuletzt bearbeitet 21.11.2024 06:25:57

Synapse is a package for Matrix homeservers written in Python 3/Twisted. Prior to version 1.47.1, Synapse instances with the media repository enabled can be tricked into downloading a file from a remote server into an arbitrary directory. No authenti...