matrix-sydent
PyPI7 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting matrix-sydentpage 1 of 1
- CVE-2019-11340MEDIUMCVSS 5.9EG 5.9✓ Fixed in 1.0.22019-04-19
util/emailutils.py in Matrix Sydent before 1.0.2 mishandles registration restrictions that are based on e-mail domain, if the allowed_local_3pids option is enabled. This occurs because of potentially unwanted behavior in Python, in which a…
- CVE-2019-11842HIGHCVSS 7.5EG 7.5✓ Fixed in 1.0.32019-05-09
An issue was discovered in Matrix Sydent before 1.0.3 and Synapse before 0.99.3.1. Random number generation is mishandled, which makes it easier for attackers to predict a Sydent authentication token or a Synapse random ID.
- CVE-2021-29430HIGHCVSS 7.5EG 7.5✓ Fixed in 2.3.02021-04-15
vulnerable: 2.0.0, 2.0.1, 2.1.0, 2.2.0
Sydent is a reference Matrix identity server. Sydent does not limit the size of requests it receives from HTTP clients. A malicious user could send an HTTP request with a very large body, leading to memory exhaustion and denial of service.…
- CVE-2021-29431HIGHCVSS 7.7EG 7.7✓ Fixed in 2.3.02021-04-15
vulnerable: 2.0.0, 2.0.1, 2.1.0, 2.2.0
Sydent is a reference Matrix identity server. Sydent can be induced to send HTTP GET requests to internal systems, due to lack of parameter validation or IP address blacklisting. It is not possible to exfiltrate data or control request hea…
- CVE-2021-29432MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2.3.02021-04-15
vulnerable: 2.0.0, 2.0.1, 2.1.0, 2.2.0
Sydent is a reference matrix identity server. A malicious user could abuse Sydent to send out arbitrary emails from the Sydent email address. This could be used to construct plausible phishing emails, for example. This issue has been fixed…
- CVE-2021-29433MEDIUMCVSS 4.3EG 4.3✓ Fixed in 2.3.02021-04-15
vulnerable: 2.0.0, 2.0.1, 2.1.0, 2.2.0
Sydent is a reference Matrix identity server. In Sydent versions 2.2.0 and prior, sissing input validation of some parameters on the endpoints used to confirm third-party identifiers could cause excessive use of disk space and memory leadi…
- CVE-2023-38686CRITICALCVSS 9.3EG 9.3✓ Fixed in 2.5.62023-08-04
vulnerable: 2.0.0 ... 2.5.5 (18 versions)
Sydent is an identity server for the Matrix communications protocol. Prior to version 2.5.6, if configured to send emails using TLS, Sydent does not verify SMTP servers' certificates. This makes Sydent's emails vulnerable to interception …
Check whether matrix-sydent is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for matrix-sydent CVEs against the assets you own.
Start Free Scan →