CVE-2021-21274Medium· 4.3▾ SunlitDenial of service attack via .well-known lookups
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0.4 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
2.2%
A malicious homeserver could redirect requests to their .well-known file to a large file. This can lead to a denial of service attack where homeservers will consume significantly more resources when requesting the .well-known file of a malicious homeserver.
This affects any server which accepts federation requests from untrusted servers.
Issue is resolved by #8950. A bug not affecting the security aspects of this was fixed in #9108.
The federation_domain_whitelist setting can be used to restrict the homeservers communicated with over federation.
matrix-synapse >= 0.99.0, < 1.25.0Upgrade to a patched release:
matrix-synapse 1.25.0Connected by shared product, vendor, weakness, or advisory.
CVE-2021-21273Low· 3.1Open redirects on some federation and push requests
CVE-2021-29471Low· 3.7Denial of service attack via push rule patterns in matrix-synapse
CVE-2021-21394Medium· 5.3Denial of service (via resource exhaustion) due to improper input validation on third-party identifier endpoints
CVE-2021-21393Medium· 5.3Denial of service (via resource exhaustion) due to improper input validation on groups/communities endpoints
CVE-2021-21333Medium· 6.1HTML injection in email and account expiry notifications
CVE-2021-21392Medium· 6.3Open redirect via transitional IPv6 addresses on dual-stack networks