CVE-2023-41335
Temporary storage of plaintext passwords during password changes in matrix synapse
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. When users update their passwords, the new credentials may be briefly held in the server database. While this doesn't grant the server any added capabilities—it already learns the users' passwords as part of the authentication process—it does disrupt the expectation that passwords won't be stored in the database. As a result, these passwords could inadvertently be captured in database backups for a longer duration. These temporarily stored passwords are automatically erased after a 48-hour window. This issue has been addressed in version 1.93.0. Users are advised to upgrade. There are no known workarounds for this issue.
Synapse es un servidor doméstico Matrix de código abierto escrito y mantenido por la Fundación Matrix.org. Cuando los usuarios actualizan sus contraseñas, las nuevas credenciales pueden guardarse brevemente en la base de datos del servidor. Si bien esto no otorga al servidor ninguna capacidad adicional (ya aprende las contraseñas de los usuarios como parte del proceso de autenticación), sí interrumpe la expectativa de que las contraseñas no se almacenen en la base de datos. Como resultado, estas contraseñas podrían quedar capturadas inadvertidamente en las copias de seguridad de la base de datos durante un período más prolongado. Estas contraseñas almacenadas temporalmente se borran automáticamente después de un período de 48 horas. Este problema se solucionó en la versión 1.93.0. Se recomienda a los usuarios que actualicen. No se conocen workarounds para este problema.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-08-28 CVE Reserved
- 2023-09-26 CVE Published
- 2024-08-02 CVE Updated
- 2024-10-02 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-312: Cleartext Storage of Sensitive Information
CAPEC
References (6)
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/matrix-org/synapse/pull/16272 | 2024-01-07 | |
https://github.com/matrix-org/synapse/security/advisories/GHSA-4f74-84v3-j9q5 | 2024-01-07 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Matrix Search vendor "Matrix" | Synapse Search vendor "Matrix" for product "Synapse" | >= 1.66.0 < 1.93.0 Search vendor "Matrix" for product "Synapse" and version " >= 1.66.0 < 1.93.0" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 37 Search vendor "Fedoraproject" for product "Fedora" and version "37" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 38 Search vendor "Fedoraproject" for product "Fedora" and version "38" | - |
Affected
|