CVE-2021-21333: HTML injection in email and account expiry notifications
(updated )
The notification emails sent for notifications for missed messages or for an expiring account are subject to HTML injection. In the case of the notification for missed messages, this could allow an attacker to insert forged content into the email.
The account expiry feature is not enabled by default and the HTML injection is not controllable by an attacker.
References
- github.com/advisories/GHSA-c5f8-35qr-q4fm
- github.com/matrix-org/synapse
- github.com/matrix-org/synapse/commit/e54746bdf7d5c831eabe4dcea76a7626f1de73df
- github.com/matrix-org/synapse/pull/9200
- github.com/matrix-org/synapse/releases/tag/v1.27.0
- github.com/matrix-org/synapse/security/advisories/GHSA-c5f8-35qr-q4fm
- github.com/pypa/advisory-database/tree/main/vulns/matrix-synapse/PYSEC-2021-134.yaml
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TNNAJOZNMVMXM6AS7RFFKB4QLUJ4IFEY
- nvd.nist.gov/vuln/detail/CVE-2021-21333
Detect and mitigate CVE-2021-21333 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →