Medium severity5.3NVD Advisory· Published Oct 31, 2023· Updated Jun 17, 2026
CVE-2023-43796
CVE-2023-43796
Description
Synapse is an open-source Matrix homeserver Prior to versions 1.95.1 and 1.96.0rc1, cached device information of remote users can be queried from Synapse. This can be used to enumerate the remote users known to a homeserver. System administrators are encouraged to upgrade to Synapse 1.95.1 or 1.96.0rc1 to receive a patch. As a workaround, the federation_domain_whitelist can be used to limit federation traffic with a homeserver.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
matrix-synapsePyPI | < 1.95.1 | 1.95.1 |
Affected products
6cpe:2.3:a:matrix:synapse:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:matrix:synapse:*:*:*:*:*:*:*:*range: <1.95.1
- (no CPE)range: < 1.95.1
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
- ghsa-coords2 versions
< 1.95.1+ 1 more
- (no CPE)range: < 1.95.1
- (no CPE)range: < 1.95.1-1.1
Patches
Vulnerability mechanics
References
10- github.com/matrix-org/synapse/commit/daec55e1fe120c564240c5386e77941372bf458fnvdPatchWEB
- github.com/advisories/GHSA-mp92-3jfm-3575ghsaADVISORY
- github.com/matrix-org/synapse/security/advisories/GHSA-mp92-3jfm-3575nvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2023-43796ghsaADVISORY
- github.com/pypa/advisory-database/tree/main/vulns/matrix-synapse/PYSEC-2023-230.yamlghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/2IDEEZMFJBDLTFHQUTZRJJNCOZGQ2ZVSghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/2IDEEZMFJBDLTFHQUTZRJJNCOZGQ2ZVS/nvdMailing List
- lists.fedoraproject.org/archives/list/[email protected]/message/VH3RNC5ZPQZ4OKPSL4E6BBJSZOQLGDEYghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/VH3RNC5ZPQZ4OKPSL4E6BBJSZOQLGDEY/nvdMailing List
- security.gentoo.org/glsa/202401-12nvdWEB
News mentions
0No linked articles in our index yet.