Executive brief
Synapse, a popular server for the Matrix communication protocol, contains a flaw in how it handles media files. Unauthorized remote users can force a server to download and store arbitrary files from other servers, which then become publicly available on the local server. This could allow malicious actors to host illegal or problematic content on a company's infrastructure without permission, potentially leading to reputational damage or legal issues.
Technical details
A missing authentication vulnerability (CWE-306) exists in Synapse's media repository before version 1.106. By design, unauthenticated remote participants can trigger a download and caching mechanism that fetches media from a remote homeserver to the local repository. Once cached, this content is accessible via unauthenticated local endpoints. Attackers can exploit this to plant arbitrary or malicious content on a target homeserver. Synapse 1.106 introduces authenticated media endpoints as a partial mitigation, with plans to deprecate unauthenticated access in future releases.
Affected products
- Matrix.org Synapse < 1.106
Timeline
- 2024-12-03: disclosed
- 2024-12-03: advisory
- 2024-12-03: patched: Fixed in version 1.106
References
- https://github.com/element-hq/synapse/security/advisories/GHSA-gjgr-7834-rhxr
- https://github.com/matrix-org/matrix-spec-proposals/pull/3916
- https://github.com/pypa/advisory-database/tree/main/vulns/matrix-synapse/PYSEC-2024-287.yaml
- https://api.github.com/repos/element-hq/synapse/security-advisories/GHSA-gjgr-7834-rhxr