Bug 1184872 - (CVE-2021-21333) VUL-0: CVE-2021-21333: matrix-synapse: HTML injection in email and account expiry notifications
(CVE-2021-21333)
VUL-0: CVE-2021-21333: matrix-synapse: HTML injection in email and account ex...
Status: NEW
Classification: openSUSE
Product: openSUSE Distribution
Classification: openSUSE
Component: Security
Leap 15.2
Other Other
: P3 - Medium : Normal (vote)
: ---
Assigned To: Oliver Kurz
Security Team bot
https://smash.suse.de/issue/280573/
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2021-04-16 12:17 UTC by Alexandros Toptsoglou
Modified: 2021-04-16 13:15 UTC (History)
0 users

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexandros Toptsoglou 2021-04-16 12:17:05 UTC
CVE-2021-21333

In Synapse before version 1.27.0, the notification emails sent for notifications for missed messages or for an expiring account are subject to HTML injection. In the case of the notification for missed messages, this could allow an attacker to insert forged content into the email. The account expiry feature is not enabled by default and the HTML injection is not controllable by an attacker. This is fixed in version 1.27.0.

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1944138
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-21333
https://github.com/matrix-org/synapse/pull/9200
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21333
https://github.com/matrix-org/synapse/security/advisories/GHSA-c5f8-35qr-q4fm
https://github.com/matrix-org/synapse/releases/tag/v1.27.0
https://github.com/matrix-org/synapse/commit/e54746bdf7d5c831eabe4dcea76a7626f1de73df