vulnerability
FreeBSD: VID-5F39D80F-107C-11EB-8B47-641C67A117D8 (CVE-2020-26891): py-matrix-synapse -- XSS vulnerability
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
4 | (AV:N/AC:M/Au:N/C:N/I:P/A:N) | Oct 1, 2020 | Oct 18, 2020 | Oct 28, 2020 |
Description
Details for this vulnerability have not been published by NIST at this point. Descriptions from software vendor advisories for this issue are provided below.
From VID-5F39D80F-107C-11EB-8B47-641C67A117D8:
Matrix developers reports:
The fallback authentication endpoint served via Synapse were vulnerable
to cross-site scripting (XSS) attacks. The impact depends on the
configuration of the domain that Synapse is deployed on, but may allow
access to cookies and other browser data, CSRF vulnerabilities, and
access to other resources served on the same domain or parent domains.
Solution(s)
References

Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.