Improper access control in Synapse - CVE-2023-43796

 

Improper access control in Synapse - CVE-2023-43796

Published: October 31, 2023 / Updated: May 4, 2026


Vulnerability identifier: #VU129610
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-43796
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper access control in cached remote user device information handling when querying device information. A remote attacker can query cached device information of remote users to disclose sensitive information.

This can be used to enumerate remote users known to the homeserver.


Affected software

Synapse
Gentoo Linux
Fedora
matrix-synapse
net-im/synapse

How to mitigate CVE-2023-43796

Install security update from vendor's website.

Synapse - addressed in versions 1.95.1, 1.96.0
matrix-synapse - addressed in versions 1.95.1-1.fc38, 1.95.1-1.fc39
net-im/synapse - update to 1.96.0

External References

Related Security Bulletins