CVE-2021-21392
Last modified
CVE-2021-21392 is a medium-severity vulnerability rated 6.3/10 on the CVSS scale. Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. EPSS estimates a 0.89% chance of exploitation in the next 30 days.
Description
Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.28.0 requests to user provided domains were not restricted to external IP addresses when transitional IPv6 addresses were used. Outbound requests to federation, identity servers, when calculating the key validity for third-party invite events, sending push notifications, and generating URL previews are affected. This could cause Synapse to make requests to internal infrastructure on dual-stack networks. See referenced GitHub security advisory for details and workarounds.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Matrix | Synapse | < 1.28.0 |
| Fedoraproject | Fedora | 34 |
References
- https://github.com/matrix-org/synapse/pull/9240Patch, Third Party Advisory
- https://github.com/matrix-org/synapse/security/advisories/GHSA-5wrh-4jwv-5w78Patch, Third Party Advisory
- https://pypi.org/project/matrix-synapse/Product, Third Party Advisory
- https://github.com/matrix-org/synapse/pull/9240Patch, Third Party Advisory
- https://github.com/matrix-org/synapse/security/advisories/GHSA-5wrh-4jwv-5w78Patch, Third Party Advisory
- https://pypi.org/project/matrix-synapse/Product, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-21392?
How severe is CVE-2021-21392?
How do I fix CVE-2021-21392?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-21386APKLeaks is an open-source project for scanning APK file for…9.8
- CVE-2021-21387Wrongthink peer-to-peer, end-to-end encrypted messenger with…7.5
- CVE-2021-21388systeminformation is an open source system and OS informatio…9.8
- CVE-2021-21389BuddyPress is an open source WordPress plugin to build a com…8.8
- CVE-2021-21390MinIO is an open-source high performance object storage serv…5.9
- CVE-2021-21391CKEditor 5 provides a WYSIWYG editing solution. This CVE aff…6.5
- CVE-2021-21393Synapse is a Matrix reference homeserver written in python (…6.5
- CVE-2021-21394Synapse is a Matrix reference homeserver written in python (…6.5
- CVE-2021-21395Magneto LTS (Long Term Support) is a community developed alt…4.3
- CVE-2021-21396wire-server is an open-source back end for Wire, a secure co…6.5
- CVE-2021-21398PrestaShop is a fully scalable open source e-commerce soluti…5.4
- CVE-2021-21399Ampache is a web based audio/video streaming application and…7.5
Are you affected by CVE-2021-21392?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
