CVE-2024-52815

Synapse is an open-source Matrix homeserver. Synapse versions before 1.120.1 fail to properly validate invites received over federation. This vulnerability allows a malicious server to send a specially crafted invite that disrupts the invited user's /sync functionality. Synapse 1.120.1 rejects such invalid invites received over federation and restores the ability to sync for affected users.
CVSS

No CVSS.

Configurations

No configuration.

History

03 Dec 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-03 17:15

Updated : 2024-12-03 17:15


NVD link : CVE-2024-52815

Mitre link : CVE-2024-52815

CVE.ORG link : CVE-2024-52815


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation