Matrix-Org / Synapse
24 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2023-43796 | Synapse vulnerable to leak of remote user device information | MEDIUM | 5.3 | Oct 31, 2023 |
| CVE-2023-45129 | matrix-synapse vulnerable to denial of service due to malicious server ACL events | MEDIUM | 6.9 | Oct 10, 2023 |
| CVE-2023-41335 | Temporary storage of plaintext passwords during password changes in matrix synapse | LOW | 2.0 | Sep 26, 2023 |
| CVE-2023-42453 | Improper validation of receipts allows forged read receipts in matrix synapse | MEDIUM | 6.3 | Sep 26, 2023 |
| CVE-2023-32683 | URL deny list bypass via oEmbed and image URLs when generating previews in Synapse | MEDIUM | 5.1 | Jun 6, 2023 |
| CVE-2023-32682 | Improper checks for deactivated users during login in synapse | MEDIUM | 5.3 | Jun 6, 2023 |
| CVE-2022-39374 | Synapse Denial of service due to incorrect application of event authorization rules during state resolution | HIGH | 7.1 | May 26, 2023 |
| CVE-2022-39335 | Synapse does not apply enough checks to servers requesting auth events of events in a room | HIGH | 7.7 | May 26, 2023 |
| CVE-2023-32323 | Synapse Outgoing federation to specific hosts can be disabled by sending malicious invites | MEDIUM | 5.3 | May 26, 2023 |
| CVE-2022-41952 | Uncontrolled Resource Consumption in Matrix Synapse | MEDIUM | 6.5 | Nov 22, 2022 |
| CVE-2022-31152 | Synapse vulnerable to denial of service (DoS) due to incorrect application of event authorization rules | HIGH | 8.7 | Sep 2, 2022 |
| CVE-2022-31052 | URL previews can crash Synapse media repositories or Synapse monoliths | HIGH | 7.1 | Jun 28, 2022 |
| CVE-2021-41281 | Path traversal in Matrix Synapse | HIGH | 8.7 | Nov 23, 2021 |
| CVE-2021-39164 | Improper authorisation of /members discloses room membership to non-members | LOW | 3.1 | Aug 31, 2021 |
| CVE-2021-39163 | Adding a private/unlisted room to a community exposes room metadata in an unauthorised manner. | LOW | 2.3 | Aug 31, 2021 |
| CVE-2021-29471 | Denial of service in Matrix Synapse | MEDIUM | 6.3 | May 11, 2021 |
| CVE-2021-21392 | Open redirect via transitional IPv6 addresses on dual-stack networks | HIGH | 7.1 | Apr 12, 2021 |
| CVE-2021-21393 | Denial of service (via resource exhaustion) due to improper input validation on groups/communities endpoints | MEDIUM | 6.0 | Apr 12, 2021 |
| CVE-2021-21394 | Denial of service (via resource exhaustion) due to improper input validation on third-party identifier endpoints | MEDIUM | 6.0 | Apr 12, 2021 |
| CVE-2021-21333 | HTML injection in email and account expiry notifications | MEDIUM | 4.9 | Mar 26, 2021 |
| CVE-2021-21332 | Cross-site scripting (XSS) vulnerability in the password reset endpoint | MEDIUM | 5.1 | Mar 26, 2021 |
| CVE-2021-21273 | Open redirects on some federation and push requests | MEDIUM | 6.3 | Feb 26, 2021 |
| CVE-2021-21274 | Denial of service attack via .well-known lookups | MEDIUM | 5.3 | Feb 26, 2021 |
| CVE-2020-26257 | Denial of service attack via incorrect parameters to federation APIs | HIGH | 7.1 | Dec 9, 2020 |
Showing 1 to 24 of 24 CVEs