CVE-2021-21273
Last modified
CVE-2021-21273 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. EPSS estimates a 1.81% chance of exploitation in the next 30 days.
Description
Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.25.0, requests to user provided domains were not restricted to external IP addresses when calculating the key validity for third-party invite events and sending push notifications. This could cause Synapse to make requests to internal infrastructure. The type of request was not controlled by the user, although limited modification of request bodies was possible. For the most thorough protection server administrators should remove the deprecated `federation_ip_range_blacklist` from their settings after upgrading to Synapse v1.25.0 which will result in Synapse using the improved default IP address restrictions. See the new `ip_range_blacklist` and `ip_range_whitelist` settings if more specific control is necessary.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Matrix | Synapse | < 1.25.0 |
| Fedoraproject | Fedora | 34 |
References
- https://github.com/matrix-org/synapse/commit/30fba6210834a4ecd91badf0c8f3eb278b72e746Patch, Third Party Advisory
- https://github.com/matrix-org/synapse/pull/8821Patch, Third Party Advisory
- https://github.com/matrix-org/synapse/releases/tag/v1.25.0Third Party Advisory
- https://github.com/matrix-org/synapse/security/advisories/GHSA-v936-j8gp-9q3pPatch, Third Party Advisory
- https://github.com/matrix-org/synapse/commit/30fba6210834a4ecd91badf0c8f3eb278b72e746Patch, Third Party Advisory
- https://github.com/matrix-org/synapse/pull/8821Patch, Third Party Advisory
- https://github.com/matrix-org/synapse/releases/tag/v1.25.0Third Party Advisory
- https://github.com/matrix-org/synapse/security/advisories/GHSA-v936-j8gp-9q3pPatch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-21273?
How severe is CVE-2021-21273?
How do I fix CVE-2021-21273?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-21267Schema-Inspector is an open-source tool to sanitize and vali…7.5
- CVE-2021-21269Keymaker is a Mastodon Community Finder based Matrix Communi…6.5
- CVE-2021-2127Vulnerability in the Oracle VM VirtualBox product of Oracle …4.4
- CVE-2021-21270OctopusDSC is a PowerShell module with DSC resources that ca…5.5
- CVE-2021-21271Tendermint Core is an open source Byzantine Fault Tolerant (…6.5
- CVE-2021-21272ORAS is open source software which enables a way to push OCI…7.7
- CVE-2021-21274Synapse is a Matrix reference homeserver written in python (…6.5
- CVE-2021-21275The MediaWiki "Report" extension has a Cross-Site Request Fo…4.3
- CVE-2021-21276Polr is an open source URL shortener. in Polr before version…9.3
- CVE-2021-21277angular-expressions is "angular's nicest part extracted as a…8.8
- CVE-2021-21278RSSHub is an open source, easy to use, and extensible RSS fe…9.8
- CVE-2021-21279Contiki-NG is an open-source, cross-platform operating syste…7.5
Are you affected by CVE-2021-21273?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
