Synapse vulnerable to leak of remote user device information
Moderate severity
GitHub Reviewed
Published
Oct 31, 2023
in
matrix-org/synapse
•
Updated Jan 8, 2024
Description
Published by the National Vulnerability Database
Oct 31, 2023
Published to the GitHub Advisory Database
Oct 31, 2023
Reviewed
Oct 31, 2023
Last updated
Jan 8, 2024
Impact
Cached device information of remote users can be queried from Synapse. This can be used to enumerate the remote users known to a homeserver.
Patches
System administrators are encouraged to upgrade to Synapse 1.95.1 as soon as possible.
Workarounds
The
federation_domain_whitelist
can be used to limit federation traffic with a homeserver.References