vulnerability

FreeBSD: VID-5F39D80F-107C-11EB-8B47-641C67A117D8 (CVE-2020-26891): py-matrix-synapse -- XSS vulnerability

Severity
4
CVSS
(AV:N/AC:M/Au:N/C:N/I:P/A:N)
Published
Oct 1, 2020
Added
Oct 18, 2020
Modified
Oct 28, 2020

Description

Details for this vulnerability have not been published by NIST at this point. Descriptions from software vendor advisories for this issue are provided below.


From VID-5F39D80F-107C-11EB-8B47-641C67A117D8:




Matrix developers reports:



The fallback authentication endpoint served via Synapse were vulnerable


to cross-site scripting (XSS) attacks. The impact depends on the


configuration of the domain that Synapse is deployed on, but may allow


access to cookies and other browser data, CSRF vulnerabilities, and


access to other resources served on the same domain or parent domains.




Solution(s)

freebsd-upgrade-package-py36-matrix-synapsefreebsd-upgrade-package-py37-matrix-synapsefreebsd-upgrade-package-py38-matrix-synapsefreebsd-upgrade-package-py39-matrix-synapse
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.