MEDIUM 5.3 PyPI

Synapse vulnerable to leak of remote user device information

GHSA-mp92-3jfm-3575 · CVE-2023-43796 · PYSEC-2023-230

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Impact

Cached device information of remote users can be queried from Synapse. This can be used to enumerate the remote users known to a homeserver.

Patches

System administrators are encouraged to upgrade to Synapse 1.95.1 as soon as possible.

Workarounds

The federation_domain_whitelist can be used to limit federation traffic with a homeserver.

Ready to move

Start Securing

Free, no credit card | First findings in minutes