Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. Prior to version 1.94.0, a malicious server ACL event can impact performance temporarily or permanently leading to a persistent denial of service. Homeservers running on a closed federation (which presumably do not need to use server ACLs) are not affected. Server administrators are advised to upgrade to Synapse 1.94.0 or later. As a workaround, rooms with malicious server ACL events can be purged and blocked using the admin API.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2023-10-10T17:17:11.146Z
Updated: 2024-08-02T20:14:19.828Z
Reserved: 2023-10-04T16:02:46.328Z
Link: CVE-2023-45129
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-10-10T18:15:19.093
Modified: 2024-11-21T08:26:24.017
Link: CVE-2023-45129
Redhat