The Sliding Sync feature on Synapse versions between 1.113.0rc1 and 1.120.0 can leak partial room state changes to users no longer in a room. Non-state events, like messages, are unaffected.
Synapse version 1.120.1 fixes the problem.
Disable Sliding Sync.
https://github.com/matrix-org/matrix-spec-proposals/pull/4186 https://github.com/element-hq/synapse/blob/d80cd57c54427687afcb48740d99219c88a0fff1/synapse/config/experimental.py#L341-L344
If you have any questions or comments about this advisory, please email us at security at element.io.
{ "nvd_published_at": "2024-12-03T17:15:12Z", "cwe_ids": [ "CWE-497" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-12-03T18:44:23Z" }