CVE-2021-21394Medium· 5.3▾ SunlitDenial of service (via resource exhaustion) due to improper input validation on third-party identifier endpoints
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
1.5%
Missing input validation of some parameters on the endpoints used to confirm third-party identifiers could cause excessive use of disk space and memory leading to resource exhaustion.
The issue is fixed by #9321.
Depending on the needs and configuration of the homeserver a few options are available:
Using email as third-party identifiers be disabled by not configuring the email setting.
Using phone numbers as third-party identifiers can be disabled by ensuring that account_threepid_delegates.msisdn is not configured.
Additionally, the affected endpoint patterns can be blocked at a reverse proxy:
^/_matrix/client/(r0|unstable)/register/email^/_matrix/client/(r0|unstable)/register/msisdn^/_matrix/client/(r0|unstable)/account/password^/_matrix/client/(r0|unstable)/account/3pidmatrix-synapse < 1.28.0Upgrade to a patched release:
matrix-synapse 1.28.0Connected by shared product, vendor, weakness, or advisory.
CVE-2021-21393Medium· 5.3Denial of service (via resource exhaustion) due to improper input validation on groups/communities endpoints
CVE-2021-21392Medium· 6.3Open redirect via transitional IPv6 addresses on dual-stack networks
CVE-2021-21274Medium· 4.3Denial of service attack via .well-known lookups
CVE-2021-29471Low· 3.7Denial of service attack via push rule patterns in matrix-synapse
CVE-2021-21273Low· 3.1Open redirects on some federation and push requests
CVE-2021-21333Medium· 6.1HTML injection in email and account expiry notifications