Synapse is an open-source Matrix homeserver. In Synapse before 1.120.1, multipart/form-data requests can in certain configurations transiently increase memory consumption beyond expected levels while processing the request, which can be used to amplify denial of service attacks. Synapse 1.120.1 resolves the issue by denying requests with unsupported multipart/form-data content type.
History

Tue, 03 Dec 2024 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Element-hq
Element-hq synapse
CPEs cpe:2.3:a:element-hq:synapse:*:*:*:*:*:*:*:*
Vendors & Products Element-hq
Element-hq synapse
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 03 Dec 2024 17:15:00 +0000

Type Values Removed Values Added
Description Synapse is an open-source Matrix homeserver. In Synapse before 1.120.1, multipart/form-data requests can in certain configurations transiently increase memory consumption beyond expected levels while processing the request, which can be used to amplify denial of service attacks. Synapse 1.120.1 resolves the issue by denying requests with unsupported multipart/form-data content type.
Title Synapse allows unsupported content types to lead to memory exhaustion
Weaknesses CWE-770
References
Metrics cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-12-03T17:01:50.119Z

Updated: 2024-12-03T19:04:44.446Z

Reserved: 2024-11-15T17:11:13.442Z

Link: CVE-2024-52805

cve-icon Vulnrichment

Updated: 2024-12-03T19:04:38.298Z

cve-icon NVD

Status : Received

Published: 2024-12-03T17:15:12.120

Modified: 2024-12-03T17:15:12.120

Link: CVE-2024-52805

cve-icon Redhat

No data.