CVE-2021-21320
low-risk
Published 2021-03-02
matrix-react-sdk is an npm package which is a Matrix SDK for React Javascript. In matrix-react-sdk before version 3.15.0, the user content sandbox can be abused to trick users into opening unexpected documents. The content is opened with a `blob` origin that cannot access Matrix user data, so messages and secrets are not at risk. This has been fixed in version 3.15.0.
Do I need to act?
-
0.18% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
2
CVSS 2.6/10
Low
NETWORK
/ HIGH complexity
Affected Products (1)
Matrix-React-Sdk
Affected Vendors
References (8)
Third Party Advisory
https://github.com/matrix-org/matrix-react-sdk/security/advisories/GHSA-52mq-6jc...
Third Party Advisory
https://github.com/matrix-org/matrix-react-sdk/security/advisories/GHSA-52mq-6jc...
16
/ 100
low-risk
Severity
10/34 · Low
Exploitability
1/34 · Minimal
Exposure
5/34 · Minimal