CVE-2020-26891: XSS
Impact The fallback authentication endpoint served via Synapse was vulnerable to cross-site scripting (XSS) attacks. The impact depends on the configuration of the domain that Synapse is deployed on, but may allow access to cookies and other browser data, CSRF vulnerabilities, and access to other resources served on the same domain or parent domains.
Patches This is fixed by #8444, which is included in Synapse v1.21.0.
Workarounds If the homeserver is not configured to use reCAPTCHA, consent (terms of service), or single sign-on then the affected endpoint can be blocked at a reverse proxy:
/matrix/client/r0/auth/./fallback/web /matrix/client/unstable/auth/./fallback/web
Other sources
AuthRestServlet in Matrix Synapse before 1.21.0 is vulnerable to XSS due to unsafe interpolation of the session GET parameter. This allows a remote attacker to execute an XSS attack on the domain Synapse is hosted on, by supplying the victim user with a malicious URL to the /matrix/client/r0/auth//fallback/web or /matrix/client/unstable/auth//fallback/web Synapse endpoints.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-26891?
CVE-2020-26891 is a vulnerability in Matrix Synapse before version 1.21.0 that allows for XSS attacks due to unsafe interpolation of the session GET parameter.
How can an attacker exploit CVE-2020-26891?
An attacker can exploit CVE-2020-26891 by supplying a malicious URL to the /_matrix/client/r0/auth/* endpoint, which can execute an XSS attack on the domain Synapse is hosted on.
What is the severity of CVE-2020-26891?
CVE-2020-26891 has a severity rating of 6.1 (Medium).
How can I fix CVE-2020-26891?
To fix CVE-2020-26891, upgrade Matrix Synapse to version 1.21.0 or later.
Where can I find more information about CVE-2020-26891?
More information about CVE-2020-26891 can be found in the references provided: [GitHub Pull Request](https://github.com/matrix-org/synapse/pull/8444), [GitHub Release](https://github.com/matrix-org/synapse/releases/tag/v1.21.2), [GitHub Security Advisory](https://github.com/matrix-org/synapse/security/advisories/GHSA-3x8c-fmpc-5rmq)