Cross-site scripting in Synapse - CVE-2021-21332

 

Cross-site scripting in Synapse - CVE-2021-21332

Published: March 25, 2021 / Updated: May 4, 2026


Vulnerability identifier: #VU129608
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2021-21332
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary script in the victim's browser.

The vulnerability exists due to cross-site scripting in the password reset endpoint when handling password reset token submission. A remote attacker can send a specially crafted request to execute arbitrary script in the victim's browser.

The impact may include access to cookies and other browser data, CSRF exposure, and access to other resources served on the same domain or parent domains.


Affected software

Synapse
Fedora
matrix-synapse

How to mitigate CVE-2021-21332

Install security update from vendor's website.

Synapse - update to 1.27.0
matrix-synapse - addressed in versions 1.38.0-2.fc34, 1.38.1-1.fc34

External References

Related Security Bulletins