Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:29979
HistoryApr 13, 2021 - 3:33 p.m.

Open Redirect

2021-04-1315:33:46
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
16
open redirect
matrix-synapse
vulnerability
federation
identity servers
push notifications
url previews
ipv6
transitional addresses
dual-stack networks

EPSS

0.001

Percentile

36.7%

matrix-synapse is vulnerable to open redirect. The requests to the user provided domains are allowed to external IP addresses while using transitional IPv6 addresses, affecting outbound requests to federation, identity servers, when calculating the key validity for third-party invite events, sending push notifications, and generating URL previews and allowing to make requests to internal infrastructure on dual-stack networks.

EPSS

0.001

Percentile

36.7%