Executive brief
Matrix Synapse is an open-source server implementation for the Matrix protocol, used to host real-time communication networks. A flaw in deactivated user validation allows deactivated accounts to regain access under specific configurations (JWT-based login or when admin-modified passwords exist on deactivated accounts), potentially enabling unauthorized access to messaging infrastructure.
Technical details
The vulnerability is an authentication bypass (CWE-287) affecting Synapse's login validation logic for deactivated user accounts. The flaw manifests under two configurations: (1) when JSON Web Token (JWT) login is enabled via jwt_config.enabled, or (2) when local password authentication is enabled and a deactivated user's password was reset via the admin API after deactivation. The attack requires no special privileges and is exploitable via the network at login time. A threat actor can authenticate as a deactivated user, gaining full access to that account. Installations using only SSO (CAS, SAML, OIDC) or external password providers (LDAP) are unaffected. Patches are available in version 1.85.0 and later.
Affected products
- Matrix.org Synapse before 1.85.0
Timeline
- 2023-06-06: disclosed
- 2023-06-06: patched: Version 1.85.0 released