synapse is vulnerable to Authentication Bypass
22
Low Risk
Affected versions of this package are affected by a vulnerability where locked users could still access authenticated HTTP endpoints using an existing session cookie, bypassing account lock restrictions. User lock status now properly invalidates active sessions across all endpoints. An attacker could exploit this by retaining a valid session cookie after account lockout, leading to unauthorized access to authenticated endpoints.
You are affected if you are using a version that falls within the vulnerable range.
synapse is vulnerable to Authentication Bypass in versions 2.177.0 - 2.203.0.
Upgrade the synapse library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant