CVE-2021-21332
In Synapse before version 1.27.0, the password reset endpoint served via Synapse was vulnerable to cross-site scripting (XSS) attacks.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.22%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.27.0, the password reset endpoint served via Synapse was vulnerable to cross-site scripting (XSS) attacks. The impact depends on the configuration of the domain that Synapse is deployed on, but may allow access to cookies and other browser data, CSRF vulnerabilities, and access to other resources served on the same domain or parent domains. This is fixed in version 1.27.0.
- CVSS 3.1
- 8.2 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
- EPSS
- 1.22% probability · 67th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- matrix/synapse · fedoraproject/fedora
- Source
- security-advisories@github.com
References
- https://github.com/matrix-org/synapse/commit/e54746bdf7d5c831eabe4dcea76a7626f1de73dfPatch, Third Party Advisory
- https://github.com/matrix-org/synapse/pull/9200Patch, Third Party Advisory
- https://github.com/matrix-org/synapse/releases/tag/v1.27.0Third Party Advisory
- https://github.com/matrix-org/synapse/security/advisories/GHSA-246w-56m2-5899Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TNNAJOZNMVMXM6AS7RFFKB4QLUJ4IFEY/
- https://github.com/matrix-org/synapse/commit/e54746bdf7d5c831eabe4dcea76a7626f1de73dfPatch, Third Party Advisory
- https://github.com/matrix-org/synapse/pull/9200Patch, Third Party Advisory
- https://github.com/matrix-org/synapse/releases/tag/v1.27.0Third Party Advisory
- https://github.com/matrix-org/synapse/security/advisories/GHSA-246w-56m2-5899Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TNNAJOZNMVMXM6AS7RFFKB4QLUJ4IFEY/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.