CVE-2023-43796: Synapse vulnerable to leak of remote user device information
Impact Cached device information of remote users can be queried from Synapse. This can be used to enumerate the remote users known to a homeserver.
Patches System administrators are encouraged to upgrade to Synapse 1.95.1 as soon as possible.
Workarounds The federationdomainwhitelist can be used to limit federation traffic with a homeserver.
Other sources
Synapse is an open-source Matrix homeserver Prior to versions 1.95.1 and 1.96.0rc1, cached device information of remote users can be queried from Synapse. This can be used to enumerate the remote users known to a homeserver. System administrators are encouraged to upgrade to Synapse 1.95.1 or 1.96.0rc1 to receive a patch. As a workaround, the federationdomainwhitelist can be used to limit federation traffic with a homeserver.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this Synapse vulnerability?
The vulnerability ID for this Synapse vulnerability is CVE-2023-43796.
What is the title of this Synapse vulnerability?
The title of this Synapse vulnerability is 'Synapse vulnerable to leak of remote user device information'.
What is the severity of CVE-2023-43796?
The severity of CVE-2023-43796 is medium with a CVSS v3.1 score of 5.3.
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by querying the cached device information of remote users from Synapse to enumerate the remote users known to a homeserver.
How can system administrators fix this vulnerability?
System administrators should upgrade to Synapse 1.95.1 or 1.96.0 to fix this vulnerability.