PT-2021-14417 · Unknown · Matrix-React-Sdk
Keerok
·
Published
2021-03-02
·
Updated
2021-03-08
·
CVE-2021-21320
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
matrix-react-sdk versions prior to 3.15.0
Description
The user content sandbox in matrix-react-sdk can be abused to trick users into opening unexpected documents. This is achieved through several user interactions, allowing the content to be opened with a
blob origin. However, it is noted that the content opened in this manner cannot access Matrix user data, so messages and secrets are not at risk.Recommendations
For versions prior to 3.15.0, update to version 3.15.0 to resolve the issue. As a temporary workaround, consider restricting user interactions that could lead to the abuse of the user content sandbox until the update is applied.
Fix
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Matrix-React-Sdk