GHSA-jhjh-776m-4765
Dashboard / Vulnerabilities / GHSA-jhjh-776m-4765
Summary: Denial of service due to incorrect application of event authorization rules
Details: ### Impact The Matrix specification specifies a list of [event authorization rules](https://spec.matrix.org/v1.3/rooms/v10/#authorization-rules) which must be checked when determining if an event should be accepted into a room. In versions of Synapse up to and including v1.61, some of these rules are not correctly applied. An attacker could craft events which would be accepted by Synapse but not a spec-conformant server, potentially causing divergence in the room state between servers. ### Patches Administrators of homeservers with federation enabled are advised to upgrade to v1.62.0 or higher. ### Workarounds * Federation can be disabled by setting [`federation_domain_whitelist`](https://matrix-org.github.io/synapse/latest/usage/configuration/config_documentation.html#federation_domain_whitelist) to an empty list (`[]`). ### References * https://github.com/matrix-org/synapse/pull/13087 * https://github.com/matrix-org/synapse/pull/13088 ### For more information If you have any questions or comments about this advisory, e-mail us at [[email protected]](mailto:[email protected]).
References: https://github.com/matrix-org/synapse/security/advisories/GHSA-jhjh-776m-4765, https://nvd.nist.gov/vuln/detail/CVE-2022-31152, https://github.com/matrix-org/synapse/pull/13087, https://github.com/matrix-org/synapse/pull/13088, https://github.com/matrix-org/synapse/commit/d4b1c0d800eaa83c4d56a9cf17881ad362b9194b, https://github.com/matrix-org/synapse/commit/e16ea87d0f8c4c30cad36f85488eb1f647e640b0, https://github.com/matrix-org/synapse, https://github.com/matrix-org/synapse/releases/tag/v1.62.0, https://github.com/pypa/advisory-database/tree/main/vulns/matrix-synapse/PYSEC-2022-262.yaml
Affected packages
Package
Name: matrix-synapse
Purl: pkg:pypi/matrix-synapse
Affected ranges
Type: ECOSYSTEM
Events:
