matrix synapse 未加控制的资源消耗(资源穷尽)

admin 2023-11-30 05:01:29 Ali_nvd 来源:ZONE.CI 全球网 0 阅读模式
中危 matrix synapse 未加控制的资源消耗(资源穷尽)

CVE编号

CVE-2022-41952

利用情况

暂无

补丁情况

官方补丁

披露时间

2022-11-23
漏洞描述
Synapse before 1.52.0 with URL preview functionality enabled will attempt to generate URL previews for media stream URLs without properly limiting connection time. Connections will only be terminated after `max_spider_size` (default: 10M) bytes have been downloaded, which can in some cases lead to long-lived connections towards the streaming media server (for instance, Icecast). This can cause excessive traffic and connections toward such servers if their stream URL is, for example, posted to a large room with many Synapse instances with URL preview enabled. Version 1.52.0 implements a timeout mechanism which will terminate URL preview connections after 30 seconds. Since generating URL previews for media streams is not supported and always fails, 1.53.0 additionally implements an allow list for content types for which Synapse will even attempt to generate a URL preview. Upgrade to 1.53.0 to fully resolve the issue. As a workaround, turn off URL preview functionality by setting `url_preview_enabled: false` in the Synapse configuration file.
解决建议
建议您更新当前系统或软件至最新版,完成漏洞的修复。
参考链接
https://github.com/matrix-org/synapse/pull/11784
https://github.com/matrix-org/synapse/pull/11936
https://github.com/matrix-org/synapse/releases/tag/v1.52.0
https://github.com/matrix-org/synapse/releases/tag/v1.53.0
https://github.com/matrix-org/synapse/security/advisories/GHSA-4822-jvwx-w47h
受影响软件情况
# 类型 厂商 产品 版本 影响面
1
运行在以下环境
应用 matrix synapse * Up to (excluding) 1.53.0
运行在以下环境
系统 debian_12 matrix-synapse * Up to (excluding) 1.53.0-1
运行在以下环境
系统 debian_sid matrix-synapse * Up to (excluding) 1.53.0-1
阿里云评分 4.8
  • 攻击路径 本地
  • 攻击复杂度 困难
  • 权限要求 管控权限
  • 影响范围 有限影响
  • EXP成熟度 未验证
  • 补丁情况 官方补丁
  • 数据保密性 无影响
  • 数据完整性 无影响
  • 服务器危害 无影响
  • 全网数量 N/A
CWE-ID 漏洞类型
CWE-400 未加控制的资源消耗(资源穷尽)
CWE-772 对已超过有效生命周期的资源丧失索引
- avd.aliyun.com
weinxin
版权声明
本站原创文章转载请注明文章出处及链接,谢谢合作!
N/A Ali_nvd

N/A

N/ACVE编号 CVE-2024-9120利用情况 暂无补丁情况 N/A披露时间 2024-09-23漏洞描述Use after free in Dawn
评论:0   参与:  0