Lucene search

K
ubuntucveUbuntu.comUB:CVE-2021-21333
HistoryMar 26, 2021 - 12:00 a.m.

CVE-2021-21333

2021-03-2600:00:00
ubuntu.com
ubuntu.com
21
synapse
matrix
python
html injection
vulnerability
cve-2021-21333
fix
version 1.27.0

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:H/A:N

EPSS

0.001

Percentile

44.0%

Synapse is a Matrix reference homeserver written in python (pypi package
matrix-synapse). Matrix is an ecosystem for open federated Instant
Messaging and VoIP. In Synapse before version 1.27.0, the notification
emails sent for notifications for missed messages or for an expiring
account are subject to HTML injection. In the case of the notification for
missed messages, this could allow an attacker to insert forged content into
the email. The account expiry feature is not enabled by default and the
HTML injection is not controllable by an attacker. This is fixed in version
1.27.0.

Bugs

OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchmatrix-synapse< anyUNKNOWN
ubuntu20.04noarchmatrix-synapse< anyUNKNOWN

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:H/A:N

EPSS

0.001

Percentile

44.0%