Synapse is an open-source Matrix homeserver. In Synapse before 1.120.1, multipart/form-data requests can in certain configurations transiently increase memory consumption beyond expected levels while processing the request, which can be used to amplify denial of service attacks. Synapse 1.120.1 resolves the issue by denying requests with unsupported multipart/form-data content type.
Metrics
Affected Vendors & Products
References
History
Tue, 03 Dec 2024 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Element-hq
Element-hq synapse |
|
CPEs | cpe:2.3:a:element-hq:synapse:*:*:*:*:*:*:*:* | |
Vendors & Products |
Element-hq
Element-hq synapse |
|
Metrics |
ssvc
|
Tue, 03 Dec 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Synapse is an open-source Matrix homeserver. In Synapse before 1.120.1, multipart/form-data requests can in certain configurations transiently increase memory consumption beyond expected levels while processing the request, which can be used to amplify denial of service attacks. Synapse 1.120.1 resolves the issue by denying requests with unsupported multipart/form-data content type. | |
Title | Synapse allows unsupported content types to lead to memory exhaustion | |
Weaknesses | CWE-770 | |
References |
| |
Metrics |
cvssV4_0
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-12-03T17:01:50.119Z
Updated: 2024-12-03T19:04:44.446Z
Reserved: 2024-11-15T17:11:13.442Z
Link: CVE-2024-52805
Vulnrichment
Updated: 2024-12-03T19:04:38.298Z
NVD
Status : Received
Published: 2024-12-03T17:15:12.120
Modified: 2024-12-03T17:15:12.120
Link: CVE-2024-52805
Redhat
No data.