CVE-2021-21320: User content sandbox can be confused into opening arbitrary documents
matrix-react-sdk is an npm package which is a Matrix SDK for React Javascript. In matrix-react-sdk before version 3.15.0, the user content sandbox can be abused to trick users into opening unexpected documents. The content is opened with a blob origin that cannot access Matrix user data, so messages and secrets are not at risk. This has been fixed in version 3.15.0.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-21320?
CVE-2021-21320 is classified as a moderate severity vulnerability.
How do I fix CVE-2021-21320?
To fix CVE-2021-21320, upgrade the matrix-react-sdk package to version 3.15.0 or later.
What type of vulnerability is CVE-2021-21320?
CVE-2021-21320 is an issue related to unsanitized user content that can exploit the content sandbox.
Who is affected by CVE-2021-21320?
Users of matrix-react-sdk versions prior to 3.15.0 are affected by CVE-2021-21320.
Can CVE-2021-21320 lead to data exposure?
Yes, CVE-2021-21320 can potentially lead to unauthorized access to unexpected documents.