Improper Authentication in Synapse - #VU23098

 

Improper Authentication in Synapse - #VU23098

Published: November 29, 2019


Vulnerability identifier: #VU23098
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to the application does not remove local threepids upon user deactivation and allows access for deactivated accounts.The problem resides within the "/synapse/storage/data_stores/main/registration.py" and "/synapse/handlers/deactivate_account.py" scripts.

A remote attacker can bypass authentication and gain unauthorized access to the application.


Affected software

Synapse

Remediation

Install updates from vendor's website.

Synapse - update to 1.6.1

External References

Related Security Bulletins