PT-2021-14380 · Matrix+1 · Synapse+1

Published

2021-02-24

·

Updated

2021-11-23

·

CVE-2021-21273

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: Synapse versions prior to 1.25.0
Description: The issue concerns Synapse, a Matrix reference homeserver written in python, where requests to user-provided domains were not restricted to external IP addresses when calculating key validity for third-party invite events and sending push notifications. This could cause Synapse to make requests to internal infrastructure. The type of request was not controlled by the user, although limited modification of request bodies was possible.
Recommendations: For Synapse versions prior to 1.25.0, upgrade to Synapse version 1.25.0. After upgrading, remove the deprecated federation ip range blacklist from settings to use the improved default IP address restrictions. Consider using the new ip range blacklist and ip range whitelist settings for more specific control if necessary. As a temporary workaround, consider blocking requests to internal IP addresses at the system or network level.

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1385
CVE-2021-21273
GHSA-V936-J8GP-9Q3P
PYSEC-2021-131

Affected Products

Alt Linux
Synapse