Bug ID 1182897
Summary VUL-0: CVE-2021-21273: matrix-synapse: user provided domains were not restricted to external IP addresses
Classification openSUSE
Product openSUSE Distribution
Version Leap 15.2
Hardware Other
URL https://smash.suse.de/issue/278709/
OS Other
Status NEW
Severity Minor
Priority P5 - None
Component Basesystem
Assignee okurz@suse.com
Reporter abergmann@suse.com
QA Contact security-team@suse.de
Found By Security Response Team
Blocker ---

CVE-2021-21273

Synapse is a Matrix reference homeserver written in python (pypi package
matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging
and
VoIP. In Synapse before version 1.25.0, requests to user provided domains were
not restricted to external IP addresses when calculating the key validity for
third-party invite events and sending push notifications. This could cause
Synapse to make requests to internal infrastructure. The type of request was
not
controlled by the user, although limited modification of request bodies was
possible. For the most thorough protection server administrators should remove
the deprecated `federation_ip_range_blacklist` from their settings after
upgrading to Synapse v1.25.0 which will result in Synapse using the improved
default IP address restrictions. See the new `ip_range_blacklist` and
`ip_range_whitelist` settings if more specific control is necessary.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-21273
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21273
https://github.com/matrix-org/synapse/commit/30fba6210834a4ecd91badf0c8f3eb278b72e746
https://github.com/matrix-org/synapse/pull/8821
https://github.com/matrix-org/synapse/releases/tag/v1.25.0
https://github.com/matrix-org/synapse/security/advisories/GHSA-v936-j8gp-9q3p


You are receiving this mail because: