CVE-2021-29471Low· 3.7▾ SunlitDenial of service attack via push rule patterns in matrix-synapse
▾ Sunlit zone — Low / medium · no exploitation signal
impact 20.4 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
1.6%
"Push rules" can specify conditions under which they will match, including event_match, which matches event content against a pattern including wildcards.
Certain patterns can cause very poor performance in the matching engine, leading to a denial-of-service when processing moderate length events.
The issue is patched by https://github.com/matrix-org/synapse/commit/03318a766cac9f8b053db2214d9c332a977d226c.
A potential workaround might be to prevent users from making custom push rules, by blocking such requests at a reverse-proxy.
If you have any questions or comments about this advisory, email us at [email protected].
matrix-synapse < 1.33.2Upgrade to a patched release:
matrix-synapse 1.33.2Connected by shared product, vendor, weakness, or advisory.
CVE-2021-21274Medium· 4.3Denial of service attack via .well-known lookups
CVE-2021-21394Medium· 5.3Denial of service (via resource exhaustion) due to improper input validation on third-party identifier endpoints
CVE-2021-21273Low· 3.1Open redirects on some federation and push requests
CVE-2021-21393Medium· 5.3Denial of service (via resource exhaustion) due to improper input validation on groups/communities endpoints
CVE-2021-21333Medium· 6.1HTML injection in email and account expiry notifications
CVE-2021-21392Medium· 6.3Open redirect via transitional IPv6 addresses on dual-stack networks