FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

py-matrix-synapse -- weakness in auth chain indexing allows DoS

Affected packages
py310-matrix-synapse < 1.105.1
py311-matrix-synapse < 1.105.1
py38-matrix-synapse < 1.105.1
py39-matrix-synapse < 1.105.1

Details

VuXML ID bdfa6c04-027a-11ef-9c21-901b0e9408dc
Discovery 2024-04-23
Entry 2024-04-24

Matrix developers report:

Weakness in auth chain indexing allows DoS from remote room members through disk fill and high CPU usage. (High severity)

References

CVE Name CVE-2024-31208
URL https://element.io/blog/security-release-synapse-1-105-1/
URL https://github.com/element-hq/synapse/security/advisories/GHSA-3h7q-rfh9-xm4v