← Back to CVE List
Vulnerability Intelligence Report
URL deny list bypass via oEmbed and image URLs when generating previews in Synapse

CVE-2023-32683

Synapse is a Matrix protocol homeserver written in Python with the Twisted framework. A discovered oEmbed or image URL can bypass the `url_preview_url_blacklist` setting potentially allowing server side request forgery or bypassing network policies. Impact is limited to IP addresses allowed by the `url_preview_ip_range_blacklist` setting (by default this only allows public IPs) and by the limited information returned to the client: 1. For discovered oEmbed URLs, any non-JSON response or a JSON response which includes non-oEmbed information is discarded. 2. For discovered image URLs, any non-image response is discarded. Systems which have URL preview disabled (via the `url_preview_enabled` setting) or have not configured a `url_preview_url_blacklist` are not affected. This issue has been addressed in version 1.85.0. Users are advised to upgrade. User unable to upgrade may also disable URL previews.

No Active Exploit Signals
CVSS Base Score
3.5
LOW
Exploitability:2.1
Impact Score:1.5
EPSS Probability:0.60%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-863 ↗CWE-863: Incorrect Authorization

Affected Products & Versions

Vendor Product Affected Versions
matrix-org synapse < 1.85.0 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.605%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityGitHub, Inc. · Vendor · USA
Reserved2023-05-11T16:33:45
Published2023-06-06T18:24:30
Last Updated2025-02-13T16:54:58

LINK COPIED TO CLIPBOARD