CVE-2024-53867

Synapse is an open-source Matrix homeserver. The Sliding Sync feature on Synapse versions between 1.113.0rc1 and 1.120.0 can leak partial room state changes to users no longer in a room. Non-state events, like messages, are unaffected. This vulnerability is fixed in 1.120.1.
Configurations

No configuration.

History

No history.

Information

Published : 2024-12-03 17:15

Updated : 2024-12-03 17:15


NVD link : CVE-2024-53867

Mitre link : CVE-2024-53867

CVE.ORG link : CVE-2024-53867


JSON object : View

Products Affected

No product.

CWE
CWE-497

Exposure of Sensitive System Information to an Unauthorized Control Sphere