Lucene search

K
freebsdFreeBSDA67E358C-0BF6-11EC-875E-901B0E9408DC
HistoryAug 31, 2021 - 12:00 a.m.

py-matrix-synapse -- several vulnerabilities

2021-08-3100:00:00
vuxml.freebsd.org
16
matrix
developers
release
patches
moderate severity
vulnerabilities
private rooms
cve-2021-39164
cve-2021-39163
metadata
unix

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:N/A:N

CVSS3

3.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

EPSS

0.001

Percentile

49.7%

Matrix developers report:

This release patches two moderate severity issues which
could reveal metadata about private rooms:

CVE-2021-39164: Enumerating a private room’s list of
members and their display names.
CVE-2021-39163: Disclosing a private room’s name,
avatar, topic, and number of members.

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:N/A:N

CVSS3

3.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

EPSS

0.001

Percentile

49.7%