Lucene search

K
ubuntucveUbuntu.comUB:CVE-2021-21274
HistoryFeb 26, 2021 - 12:00 a.m.

CVE-2021-21274

2021-02-2600:00:00
ubuntu.com
ubuntu.com
14
synapse
matrix
homeserver
denial of service
federation
vulnerability
python
voip
instant messaging

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS

0.002

Percentile

54.7%

Synapse is a Matrix reference homeserver written in python (pypi package
matrix-synapse). Matrix is an ecosystem for open federated Instant
Messaging and VoIP. In Synapse before version 1.25.0, a malicious
homeserver could redirect requests to their .well-known file to a large
file. This can lead to a denial of service attack where homeservers will
consume significantly more resources when requesting the .well-known file
of a malicious homeserver. This affects any server which accepts federation
requests from untrusted servers. Issue is resolved in version 1.25.0. As a
workaround the federation_domain_whitelist setting can be used to
restrict the homeservers communicated with over federation.

OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchmatrix-synapse< anyUNKNOWN
ubuntu20.04noarchmatrix-synapse< anyUNKNOWN

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS

0.002

Percentile

54.7%