MEDIUM 4.9 PyPI

matrix-synapse vulnerable to denial of service due to malicious server ACL events

GHSA-5chr-wjw5-3gq4 · CVE-2023-45129 · PYSEC-2023-199

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Impact

A malicious server ACL event can impact performance temporarily or permanently leading to a persistent denial of service.

Homeservers running on a closed federation (which presumably do not need to use server ACLs) are not affected.

Patches

Server administrators are advised to upgrade to Synapse 1.94.0 or later.

Workarounds

Rooms with malicious server ACL events can be purged and blocked using the admin API.

Ready to move

Start Securing

Free, no credit card | First findings in minutes