Cleartext storage of sensitive information in Synapse - CVE-2023-41335
Published: October 4, 2023
Vulnerability details
The vulnerability allows a user to gain access to sensitive information.
The vulnerability exists due to the way the application handles password change. When users update their passwords, the new credentials may be briefly held in the server database in clear text. A user with access to the database can obtain the password in clear text.
Affected software
Gentoo Linux
Fedora
matrix-synapse
net-im/synapse
How to mitigate CVE-2023-41335
matrix-synapse - addressed in versions 1.80.0-6.fc37, 1.93.0-2.fc38, 1.93.0-2.fc39
net-im/synapse - update to 1.96.0