Skip to main content

Vendor/product archive

matrix / sydent CVEs

Beta · best-effort

7 CVEs tagged to matrix / sydent1 Critical, 3 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2023-38686

Published Aug 4, 2023

Sydent is an identity server for the Matrix communications protocol. Prior to version 2.5.6, if configured to send emails using TLS, Sydent does not verify SMTP servers' certifica…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-29432

Published Apr 15, 2021

Sydent is a reference matrix identity server. A malicious user could abuse Sydent to send out arbitrary emails from the Sydent email address. This could be used to construct plaus…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-29431

Published Apr 15, 2021

Sydent is a reference Matrix identity server. Sydent can be induced to send HTTP GET requests to internal systems, due to lack of parameter validation or IP address blacklisting.…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2021-29430

Published Apr 15, 2021

Sydent is a reference Matrix identity server. Sydent does not limit the size of requests it receives from HTTP clients. A malicious user could send an HTTP request with a very lar…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-29433

Published Apr 15, 2021

Sydent is a reference Matrix identity server. In Sydent versions 2.2.0 and prior, sissing input validation of some parameters on the endpoints used to confirm third-party identifi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11842

Published May 9, 2019

An issue was discovered in Matrix Sydent before 1.0.3 and Synapse before 0.99.3.1. Random number generation is mishandled, which makes it easier for attackers to predict a Sydent…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-11340

Published Apr 19, 2019

util/emailutils.py in Matrix Sydent before 1.0.2 mishandles registration restrictions that are based on e-mail domain, if the allowed_local_3pids option is enabled. This occurs be…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-7 of 7 CVEsPage 1 of 1