CVE-2022-39374
Last modified
CVE-2022-39374 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. If Synapse and a malicious homeserver are both joined to the same room, the malicious homeserver can trick Synapse into accepting previously rejected events into its view of the current state of that room. EPSS estimates a 0.94% chance of exploitation in the next 30 days.
Description
Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. If Synapse and a malicious homeserver are both joined to the same room, the malicious homeserver can trick Synapse into accepting previously rejected events into its view of the current state of that room. This can be exploited in a way that causes all further messages and state changes sent in that room from the vulnerable homeserver to be rejected. This issue has been patched in version 1.68.0
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Matrix | Synapse | >= 1.62.0, < 1.68.0 |
References
- https://github.com/matrix-org/synapse/pull/13723Issue Tracking, Patch
- https://github.com/matrix-org/synapse/security/advisories/GHSA-p9qp-c452-f9r7Mitigation, Vendor Advisory
- https://github.com/matrix-org/synapse/pull/13723Issue Tracking, Patch
- https://github.com/matrix-org/synapse/security/advisories/GHSA-p9qp-c452-f9r7Mitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-39374?
How severe is CVE-2022-39374?
How do I fix CVE-2022-39374?
Are you affected by CVE-2022-39374?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
