CVE-2021-21274Uncontrolled Resource Consumption in Synapse

Severity
6.5MEDIUMNVD
CNA4.3
EPSS
0.4%
top 36.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 26
Latest updateMar 1

Description

Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.25.0, a malicious homeserver could redirect requests to their .well-known file to a large file. This can lead to a denial of service attack where homeservers will consume significantly more resources when requesting the .well-known file of a malicious homeserver. This affects any server which accepts federation

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

NVDmatrix/synapse0.99.01.25.0
CVEListV5matrix-org/synapse>=0.99.0, < 1.25.0

Also affects: Fedora 34

Patches

🔴Vulnerability Details

4
GHSA
Denial of service attack via .well-known lookups2021-03-01
OSV
Denial of service attack via .well-known lookups2021-03-01
CVEList
Denial of service attack via .well-known lookups2021-02-26
OSV
CVE-2021-21274: Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse)2021-02-26

📋Vendor Advisories

1
Debian
CVE-2021-21274: matrix-synapse - Synapse is a Matrix reference homeserver written in python (pypi package matrix-...2021
CVE-2021-21274 — Uncontrolled Resource Consumption | cvebase