PT-2021-14417 · Unknown · Matrix-React-Sdk

Keerok

·

Published

2021-03-02

·

Updated

2021-03-08

·

CVE-2021-21320

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions matrix-react-sdk versions prior to 3.15.0
Description The user content sandbox in matrix-react-sdk can be abused to trick users into opening unexpected documents. This is achieved through several user interactions, allowing the content to be opened with a blob origin. However, it is noted that the content opened in this manner cannot access Matrix user data, so messages and secrets are not at risk.
Recommendations For versions prior to 3.15.0, update to version 3.15.0 to resolve the issue. As a temporary workaround, consider restricting user interactions that could lead to the abuse of the user content sandbox until the update is applied.

Fix

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-21320
GHSA-52MQ-6JCV-J79X

Affected Products

Matrix-React-Sdk