
Cloud Vulnerability DB
A community-led vulnerabilities database
Synapse, a Matrix reference homeserver written in python (pypi package matrix-synapse), was found to be vulnerable to a denial of service attack via .well-known lookups. The vulnerability (CVE-2021-21274) affected versions above 0.99.0 and was patched in version 1.25.0. This security issue was discovered in February 2021 and impacted servers that accept federation requests from untrusted servers (GitHub Advisory).
A malicious homeserver could redirect requests to their .well-known file to a large file, causing the requesting server to consume significantly more resources when processing the .well-known file. The issue was resolved by implementing a maximum size limit of 50 kilobytes for .well-known lookups (GitHub PR).
The vulnerability could lead to a denial of service attack where homeservers would consume significantly more resources when requesting the .well-known file of a malicious homeserver. This affected any server which accepts federation requests from untrusted servers (GitHub Advisory).
The vulnerability was rated as Low severity. It required a malicious actor to control a homeserver that could be federated with the target server. The attack could be executed remotely without requiring authentication (GitHub Advisory).
The vulnerability was patched in version 1.25.0. As a workaround before updating, administrators could use the federation_domain_whitelist setting to restrict the homeservers communicated with over federation (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."