CVE-2024-31208
Synapse V2 state resolution weakness allows Denial of Service (DoS)
描述
Synapse is an open-source Matrix homeserver. A remote Matrix user with malicious intent, sharing a room with Synapse instances before 1.105.1, can dispatch specially crafted events to exploit a weakness in the V2 state resolution algorithm. This can induce high CPU consumption and accumulate excessive data in the database of such instances, resulting in a denial of service. Servers in private federations, or those that do not federate, are not affected. Server administrators should upgrade to 1.105.1 or later. Some workarounds are available. One can ban the malicious users or ACL block servers from the rooms and/or leave the room and purge the room using the admin API.
如何修補 CVE-2024-31208
要修補 CVE-2024-31208,請將受影響套件升級到下列已修補版本。
- —升級至 1.103.0-2 或更新版本
- —升級至 1.105.1 或更新版本
- —升級至 55b0aa847a61774b6a3acdc4b177a20dc019f01a 或更新版本
CVE-2024-31208 正在被利用嗎?
低 — EPSS 為 1.5%,目前沒有觀察到大規模利用活動。
受影響套件(3)
- from 0, < 1.103.0-2
- from 0, < 1.105.1
- from 0, < 55b0aa847a61774b6a3acdc4b177a20dc019f01a | from 0, < 1.105.1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.5 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |