SCA: security update for matrix-synapse (GHSA-7565-cq32-vx2x)

medium Tenable Self-Hosted Container Security Plugin ID 411826

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. Users
were able to forge read receipts for any event (if they knew the room ID and event ID). Note that the
users were not able to view the events, but simply mark it as read. This could be confusing as clients
will show the event as read by the user, even if they are not in the room. This issue has been patched in
version 1.93.0. Users are advised to upgrade. There are no known workarounds for this issue.
(CVE-2023-42453)

See Also

https://github.com/advisories/GHSA-7565-cq32-vx2x

Plugin Details

Severity: Medium

ID: 411826

Version: Revision 1.7

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 1.2

Percentile: 0.01

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 4

Temporal Score: 3

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:P/A:N

CVSS Score Source: CVE-2023-42453

CVSS v3

Risk Factor: Medium

Base Score: 4.3

Temporal Score: 3.8

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: Medium

Base Score: 6.3

Threat Score: 1.7

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/26/2023

Vulnerability Publication Date: 9/26/2023

Reference Information

CVE: CVE-2023-42453

cwe: CWE-285