CVE-2024-53867

Name
CVE-2024-53867
Description
Synapse is an open-source Matrix homeserver. The Sliding Sync feature on Synapse versions between 1.113.0rc1 and 1.120.0 can leak partial room state changes to users no longer in a room. Non-state events, like messages, are unaffected. This vulnerability is fixed in 1.120.1.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
CONFIRM https://github.com/element-hq/synapse/security/advisories/GHSA-56w4-5538-8v8h
MISC https://github.com/matrix-org/matrix-spec-proposals/pull/4186

Match rules

CPE URI Source package Min version Max version
synapse >= 1.113.0rc1 < 1.120.1

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
synapse edge-community 1.120.2-r0 jahway603 <jahway603@protonmail.com> fixed
synapse 3.21-community 1.120.2-r0 jahway603 <jahway603@protonmail.com> fixed