matrix-synapse is vulnerable to Authorization Bypass
48
Medium Risk
Synapse fixed an authorization bypass where non-admin users could use the admin_unsafely_bypass_quarantine=true parameter to bypass admin-only checks when downloading remote quarantined media (when the media was already present). The fix enforces proper admin-only authorization for this bypass and adds a regression test to ensure no remote media fetch occurs for non-admins. Additionally, Synapse now rejects device_keys: null in /keys/upload to prevent invalid request handling.
You are affected if you are using a version that falls within the vulnerable range.
matrix-synapse is vulnerable to Authorization Bypass in versions 1.145.0 - 1.151.0.
Upgrade the matrix-synapse library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant