CVE Vulnerabilities

CVE-2023-43796

Published: Oct 31, 2023 | Modified: Jan 07, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Synapse is an open-source Matrix homeserver Prior to versions 1.95.1 and 1.96.0rc1, cached device information of remote users can be queried from Synapse. This can be used to enumerate the remote users known to a homeserver. System administrators are encouraged to upgrade to Synapse 1.95.1 or 1.96.0rc1 to receive a patch. As a workaround, the federation_domain_whitelist can be used to limit federation traffic with a homeserver.

Affected Software

Name Vendor Start Version End Version
Synapse Matrix * 1.95.1 (excluding)
Matrix-synapse Ubuntu bionic *
Matrix-synapse Ubuntu lunar *
Matrix-synapse Ubuntu mantic *
Matrix-synapse Ubuntu trusty *
Matrix-synapse Ubuntu xenial *

References