matrix-synapse is vulnerable to Improper Handling of Exceptional Conditions
76
High Risk
For some client requests concerning remote users or rooms belonging to a malicious homeserver, Synapse makes federation requests and forwards the received errors directly back to the client. A malicious homeserver can return an unauthorized error that makes the client believe its own access token is invalid, causing it to log out and destroy its cryptographic state. Users without another client or key backup can irreversibly lose encrypted message history. The fix rewrites forwarded upstream errors and forbids the sensitive token errcode from being relayed.
You are affected if you are using a version that falls within the vulnerable range and your homeserver participates in open federation.
matrix-synapse is vulnerable to Improper Handling of Exceptional Conditions in versions 0.0.1 - 1.157.1.
Upgrade the matrix-synapse library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant