Arbitrary Code Injection Affecting synapse package, versions <1.20.0-r0


Severity

Recommended
0.0
high
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.77% (82nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-ALPINE317-SYNAPSE-3144303
  • published2 Feb 2021
  • disclosed24 Nov 2020

Introduced: 24 Nov 2020

CVE-2020-26890  (opens in a new tab)
CWE-74  (opens in a new tab)

How to fix?

Upgrade Alpine:3.17 synapse to version 1.20.0-r0 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream synapse package and not the synapse package as distributed by Alpine. See How to fix? for Alpine:3.17 relevant fixed versions and status.

Matrix Synapse before 1.20.0 erroneously permits non-standard NaN, Infinity, and -Infinity JSON values in fields of m.room.member events, allowing remote attackers to execute a denial of service attack against the federation and common Matrix clients. If such a malformed event is accepted into the room's state, the impact is long-lasting and is not fixed by an upgrade to a newer version, requiring the event to be manually redacted instead. Since events are replicated to servers of other room members, the impact is not constrained to the server of the event sender.

CVSS Scores

version 3.1