Sydent
Matrix · 7 CVEs
CVE-2023-38686
CRITICAL
Sydent does not verify email server certificates
Aug 4, 2023
CVE-2021-29431
MEDIUM
SSRF in Sydent due to missing validation of hostnames
Apr 15, 2021
CVE-2021-29432
MEDIUM
Malicious users could control the content of invitation emails
Apr 15, 2021
CVE-2021-29430
HIGH
Denial of service attack via memory exhaustion
Apr 15, 2021
CVE-2021-29433
MEDIUM
Denial of service (via resource exhaustion) due to improper input validation
Apr 15, 2021
CVE-2019-11842
HIGH
An issue was discovered in Matrix Sydent before 1.0.3 and Synapse before 0.99.3.1. Random number generation is mishandl…
May 9, 2019
CVE-2019-11340
MEDIUM
util/emailutils.py in Matrix Sydent before 1.0.2 mishandles registration restrictions that are based on e-mail domain,…
Apr 19, 2019
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2023-38686 | Sydent does not verify email server certificates | CRITICAL | 0.27% | Aug 4, 2023 |
| CVE-2021-29431 | SSRF in Sydent due to missing validation of hostnames | MEDIUM | 1.19% | Apr 15, 2021 |
| CVE-2021-29432 | Malicious users could control the content of invitation emails | MEDIUM | 0.93% | Apr 15, 2021 |
| CVE-2021-29430 | Denial of service attack via memory exhaustion | HIGH | 1.83% | Apr 15, 2021 |
| CVE-2021-29433 | Denial of service (via resource exhaustion) due to improper input validation | MEDIUM | 0.93% | Apr 15, 2021 |
| CVE-2019-11842 | An issue was discovered in Matrix Sydent before 1.0.3 and Synapse before 0.99.3.1. Random number generation is mishandled, which makes it easier for attackers… | HIGH | 1.80% | May 9, 2019 |
| CVE-2019-11340 | util/emailutils.py in Matrix Sydent before 1.0.2 mishandles registration restrictions that are based on e-mail domain, if the allowed_local_3pids option is ena… | MEDIUM | 1.88% | Apr 19, 2019 |
Showing 1 to 7 of 7 CVEs