Synapse is an open-source Matrix homeserver Prior to versions 1.95.1 and 1.96.0rc1, cached device information of remote users can be queried from Synapse. This can be used to enumerate the remote users known to a homeserver. System administrators are encouraged to upgrade to Synapse 1.95.1 or 1.96.0rc1 to receive a patch. As a workaround, the `federation_domain_whitelist` can be used to limit federation traffic with a homeserver.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2023-10-31T16:52:48.505Z
Updated: 2024-08-02T19:52:11.374Z
Reserved: 2023-09-22T14:51:42.339Z
Link: CVE-2023-43796
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-10-31T17:15:23.270
Modified: 2024-11-21T08:24:48.137
Link: CVE-2023-43796
Redhat
No data.