VendorsMatrixsydentall versions
Vulnerabilities

Matrix Sydent

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2023-38686
Sydent does not verify email server certificates
Published 2023-08-04 · Modified
9.3EPSS 0.003
CVE-2021-29431
SSRF in Sydent due to missing validation of hostnames
Published 2021-04-15 · Modified
7.7EPSS 0.012
CVE-2021-29430
Denial of service attack via memory exhaustion
Published 2021-04-15 · Modified
7.5EPSS 0.018
CVE-2019-11842
An issue was discovered in Matrix Sydent before 1.0.3 and Synapse before 0.99.3.1. Random number generation is mishandled, which makes it easier for attackers to predict a Sydent authentication token or a Synapse random ID.
Published 2019-05-09 · Modified
7.5EPSS 0.018
CVE-2019-11340
util/emailutils.py in Matrix Sydent before 1.0.2 mishandles registration restrictions that are based on e-mail domain, if the allowed_local_3pids option is enabled. This occurs because of potentially unwanted behavior in Python, in which an email.utils.parseaddr call on user@bad.example.net@good.example.com returns the user@bad.example.net substring.
Published 2019-04-19 · Modified
5.9EPSS 0.019
CVE-2021-29432
Malicious users could control the content of invitation emails
Published 2021-04-15 · Modified
5.7EPSS 0.009
CVE-2021-29433
Denial of service (via resource exhaustion) due to improper input validation
Published 2021-04-15 · Modified
4.3EPSS 0.009