CVE-2024-53867 - Synapse Sliding Sync Room State Disclosure Vulnerability

CVE ID : CVE-2024-53867 Published : Dec. 3, 2024, 5:15 p.m. | 3 hours, 14 minutes ago Description : Synapse is an open-source Matrix homeserver. The Sliding Sync feature on Synapse versions between 1.113.0rc1 and 1.120.0 can leak partial room state changes to users no longer in a room. Non-state events, like messages, are unaffected. This vulnerability is fixed in 1.120.1. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Dez 3, 2024 - 21:31
 0  2
CVE-2024-53867 - Synapse Sliding Sync Room State Disclosure Vulnerability
CVE ID : CVE-2024-53867
Published : Dec. 3, 2024, 5:15 p.m. | 3 hours, 14 minutes ago
Description : Synapse is an open-source Matrix homeserver. The Sliding Sync feature on Synapse versions between 1.113.0rc1 and 1.120.0 can leak partial room state changes to users no longer in a room. Non-state events, like messages, are unaffected. This vulnerability is fixed in 1.120.1.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...