Missing Authentication for Critical Function in Synapse - CVE-2024-37303

 

Missing Authentication for Critical Function in Synapse - CVE-2024-37303

Published: December 3, 2024 / Updated: April 23, 2026


Vulnerability identifier: #VU127004
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-37303
CWE-ID: CWE-306
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to plant problematic content in the media repository.

The vulnerability exists due to missing authentication for critical functionality in the media repository download endpoints when triggering download and caching of remote media from a remote homeserver. A remote attacker can cause the server to fetch and cache remote media to plant problematic content in the media repository.

The planted content then becomes available for unauthenticated download from the local homeserver.


Affected software

Synapse

How to mitigate CVE-2024-37303

Install security update from vendor's website.

Synapse - update to 1.106.0

External References

Related Security Bulletins