CVE-2021-21320
User content sandbox can be confused into opening arbitrary documents
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
matrix-react-sdk is an npm package which is a Matrix SDK for React Javascript. In matrix-react-sdk before version 3.15.0, the user content sandbox can be abused to trick users into opening unexpected documents. The content is opened with a `blob` origin that cannot access Matrix user data, so messages and secrets are not at risk. This has been fixed in version 3.15.0.
matrix-react-sdk es un paquete npm que es un Matrix SDK para React Javascript. En matrix-react-sdk anterior a la versión 3.15.0, el sandbox del contenido del usuario puede ser abusado para engañar a los usuarios para que abran documentos inesperados. El contenido es abierto con un origen "blob" que no puede acceder a los datos del usuario de Matrix, por lo que los mensajes y secretos no están en riesgo. Esto ha sido corregido en la versión 3.15.0
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-12-22 CVE Reserved
- 2021-03-02 CVE Published
- 2023-11-15 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-345: Insufficient Verification of Data Authenticity
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://github.com/matrix-org/matrix-react-sdk/security/advisories/GHSA-52mq-6jcv-j79x | Third Party Advisory | |
https://www.npmjs.com/package/matrix-react-sdk | Product |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/matrix-org/matrix-react-sdk/commit/b386f0c73b95ecbb6ea7f8f79c6ff5171a8dedd1 | 2021-03-08 | |
https://github.com/matrix-org/matrix-react-sdk/pull/5657 | 2021-03-08 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Matrix-react-sdk Project Search vendor "Matrix-react-sdk Project" | Matrix-react-sdk Search vendor "Matrix-react-sdk Project" for product "Matrix-react-sdk" | < 3.15.0 Search vendor "Matrix-react-sdk Project" for product "Matrix-react-sdk" and version " < 3.15.0" | node.js |
Affected
|