matrix-synapse is vulnerable to Improper Input Validation
31
Low Risk
For some HTTP request paths, Synapse ignores extraneous path segments and serves a resource at an unexpected path. Because the same resource is reachable through multiple path variants, external rate-limiting keyed on the canonical path can be evaded. The Client-Server, Federation, Admin and Key Server APIs are not affected by this malleability. The fix ensures the catch-all unrecognised-request handler cannot resolve resources under inserted path segments.
You are affected if you are using a version that falls within the vulnerable range and you rely on external path-based rate limiting in front of Synapse.
matrix-synapse is vulnerable to Improper Input Validation in versions 0.0.1 - 1.157.1.
Upgrade the matrix-synapse library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant