CVE-2024-53867 - Synapse Sliding Sync Room State Disclosure Vulnerability
CVE ID : CVE-2024-53867 Published : Dec. 3, 2024, 5:15 p.m. | 3 hours, 14 minutes ago Description : Synapse is an open-source Matrix homeserver. The Sliding Sync feature on Synapse versions between 1.113.0rc1 and 1.120.0 can leak partial room state changes to users no longer in a room. Non-state events, like messages, are unaffected. This vulnerability is fixed in 1.120.1. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
![CVE-2024-53867 - Synapse Sliding Sync Room State Disclosure Vulnerability](https://cdn.cvefeed.io/images/cvefeed.io-new.webp)
Published : Dec. 3, 2024, 5:15 p.m. | 3 hours, 14 minutes ago
Description : Synapse is an open-source Matrix homeserver. The Sliding Sync feature on Synapse versions between 1.113.0rc1 and 1.120.0 can leak partial room state changes to users no longer in a room. Non-state events, like messages, are unaffected. This vulnerability is fixed in 1.120.1.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...