5.3
CVSSv3

CVE-2023-43796

Published: 31/10/2023 Updated: 07/01/2024
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Synapse is an open-source Matrix homeserver Prior to versions 1.95.1 and 1.96.0rc1, cached device information of remote users can be queried from Synapse. This can be used to enumerate the remote users known to a homeserver. System administrators are encouraged to upgrade to Synapse 1.95.1 or 1.96.0rc1 to receive a patch. As a workaround, the `federation_domain_whitelist` can be used to limit federation traffic with a homeserver.

Vulnerable Product Search on Vulmon Subscribe to Product

matrix synapse

fedoraproject fedora 38

fedoraproject fedora 39

Vendor Advisories

Debian Bug report logs - #1055255 matrix-synapse: CVE-2023-43796 Package: src:matrix-synapse; Maintainer for src:matrix-synapse is Matrix Packaging Team <pkg-matrix-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 2 Nov 2023 21:27:02 UTC Severity: grave Tags: sec ...