PT-2021-14380 · Matrix+1 · Synapse+1
Published
2021-02-24
·
Updated
2021-11-23
·
CVE-2021-21273
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions:
Synapse versions prior to 1.25.0
Description:
The issue concerns Synapse, a Matrix reference homeserver written in python, where requests to user-provided domains were not restricted to external IP addresses when calculating key validity for third-party invite events and sending push notifications. This could cause Synapse to make requests to internal infrastructure. The type of request was not controlled by the user, although limited modification of request bodies was possible.
Recommendations:
For Synapse versions prior to 1.25.0, upgrade to Synapse version 1.25.0. After upgrading, remove the deprecated
federation ip range blacklist from settings to use the improved default IP address restrictions. Consider using the new ip range blacklist and ip range whitelist settings for more specific control if necessary. As a temporary workaround, consider blocking requests to internal IP addresses at the system or network level.Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Synapse