Junglewise Threat Intelligence

CVE-2021-21332: PYSEC-2021-133 - Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant

CVE-2021-21332 · Severity: low · CVSS 3.1 · Published 2021-03-26

Technologies: matrix-synapse (PyPI). Vendors: PyPI, Matrix.org.

Executive brief

Matrix Synapse is an open-source messaging server that powers the Matrix protocol and allows organizations to run federated communication infrastructure. A cross-site scripting (XSS) vulnerability in the password reset page could allow attackers to steal user session cookies, perform unauthorized actions, or access other resources on the same domain, potentially compromising account security and user data.

Technical details

The password reset endpoint in Matrix Synapse failed to properly escape user-controllable input in the HTML response, leading to a stored or reflected cross-site scripting (XSS) vulnerability. An attacker could craft a malicious password reset link or request to inject arbitrary JavaScript code that executes in the victim's browser when they interact with the password reset page. The vulnerability requires user interaction (clicking a malicious link or visiting a crafted page) and is network-reachable on any Synapse deployment. Successful exploitation can lead to session hijacking, CSRF attacks, and access to sensitive data depending on domain configuration. The vulnerability was fixed in version 1.27.0 released in March 2021, with a patch available in pull request #9200.

Affected products

  • Matrix.org Synapse before 1.27.0

Timeline

  • 2021-03-26: disclosed
  • 2021-03-26: patched: fixed in version 1.27.0

References

Related threats