Search CVE reports
11 – 20 of 34 results
CVE-2022-41952
Medium prioritySynapse before 1.52.0 with URL preview functionality enabled will attempt to generate URL previews for media stream URLs without properly limiting connection time. Connections will only be terminated after `max_spider_size`...
1 affected packages
matrix-synapse
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
matrix-synapse | Not affected | Not affected | Needs evaluation | Needs evaluation | Ignored |
CVE-2022-31152
Medium prioritySynapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. The Matrix specification specifies a list of [event authorization rules](https://spec.matrix.org/v1.2/rooms/v9/#authorization-rules)...
1 affected packages
matrix-synapse
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
matrix-synapse | Not affected | Needs evaluation | Needs evaluation | Needs evaluation | Ignored |
CVE-2022-31052
Medium prioritySynapse is an open source home server implementation for the Matrix chat network. In versions prior to 1.61.1 URL previews of some web pages can exhaust the available stack space for the Synapse process due to unbounded recursion....
1 affected packages
matrix-synapse
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
matrix-synapse | Not affected | Needs evaluation | Needs evaluation | Needs evaluation | Not in release |
CVE-2021-41281
Medium prioritySynapse is a package for Matrix homeservers written in Python 3/Twisted. Prior to version 1.47.1, Synapse instances with the media repository enabled can be tricked into downloading a file from a remote server into an arbitrary...
1 affected packages
matrix-synapse
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
matrix-synapse | Not affected | Vulnerable | Vulnerable | Vulnerable | Ignored |
CVE-2021-39164
Medium priorityMatrix is an ecosystem for open federated Instant Messaging and Voice over IP. In versions 1.41.0 and prior, unauthorised users can access the membership (list of members, with their display names) of a room if they know the ID of...
1 affected packages
matrix-synapse
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
matrix-synapse | Not affected | Needs evaluation | Vulnerable | Vulnerable | Ignored |
CVE-2021-39163
Medium priorityMatrix is an ecosystem for open federated Instant Messaging and Voice over IP. In versions 1.41.0 and prior, unauthorised users can access the name, avatar, topic and number of members of a room if they know the ID of the room....
1 affected packages
matrix-synapse
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
matrix-synapse | Not affected | Needs evaluation | Vulnerable | Vulnerable | Ignored |
CVE-2021-29471
Medium prioritySynapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.33.2 "Push rules" can specify conditions...
1 affected packages
matrix-synapse
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
matrix-synapse | Not affected | Vulnerable | Vulnerable | Vulnerable | Ignored |
CVE-2021-21393
Medium prioritySynapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.28.0 Synapse is missing input validation...
1 affected packages
matrix-synapse
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
matrix-synapse | Not affected | Vulnerable | Vulnerable | Not affected | Not in release |
CVE-2021-21392
Medium prioritySynapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.28.0 requests to user provided domains...
1 affected packages
matrix-synapse
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
matrix-synapse | Not affected | Vulnerable | Vulnerable | Vulnerable | Not in release |
CVE-2021-21394
Medium prioritySynapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.28.0 Synapse is missing input validation...
1 affected packages
matrix-synapse
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
matrix-synapse | Not affected | Vulnerable | Vulnerable | Vulnerable | Not in release |