Synapse is an open-source Matrix homeserver. Synapse versions before 1.120.1 fail to properly validate invites received over federation. This vulnerability allows a malicious server to send a specially crafted invite that disrupts the invited user's /sync functionality. Synapse 1.120.1 rejects such invalid invites received over federation and restores the ability to sync for affected users.
CVSS
No CVSS.
References
Configurations
No configuration.
History
03 Dec 2024, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-12-03 17:15
Updated : 2024-12-03 17:15
NVD link : CVE-2024-52815
Mitre link : CVE-2024-52815
CVE.ORG link : CVE-2024-52815
JSON object : View
Products Affected
No product.
CWE
CWE-20
Improper Input Validation