GMS-2021-169: Denial of service due to improper input validation in third-party identifier endpoint
Impact
Missing input validation of some parameters on the endpoints used to confirm third-party identifiers could cause excessive use of disk space and memory leading to resource exhaustion.
Patches
The issue is fixed by https://github.com/matrix-org/synapse/pull/9855.
Workarounds
There are no known workarounds.
References
n/a
For more information
If you have any questions or comments about this advisory, email us at security@matrix.org.
References
Detect and mitigate GMS-2021-169 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →