Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pw4v-gr34-2553

Опубликовано: 16 апр. 2021
Источник: github
Github: Прошло ревью
CVSS4: 5.3
CVSS3: 4.3

Описание

Sydent DoS (via resource exhaustion) due to improper input validation

Impact

Missing input validation of some parameters on the endpoints used to confirm third-party identifiers could cause excessive use of disk space and memory leading to resource exhaustion.

Patches

Fixed by 3175fd3.

For more information

If you have any questions or comments about this advisory, email us at security@matrix.org.

Пакеты

Наименование

matrix-sydent

pip
Затронутые версииВерсия исправления

< 2.3.0

2.3.0

EPSS

Процентиль: 51%
0.00281
Низкий

5.3 Medium

CVSS4

4.3 Medium

CVSS3

Дефекты

CWE-20
CWE-400

Связанные уязвимости

CVSS3: 4.3
nvd
почти 5 лет назад

Sydent is a reference Matrix identity server. In Sydent versions 2.2.0 and prior, sissing input validation of some parameters on the endpoints used to confirm third-party identifiers could cause excessive use of disk space and memory leading to resource exhaustion. A patch for the vulnerability is in version 2.3.0. No workarounds are known to exist.

CVSS3: 4.3
debian
почти 5 лет назад

Sydent is a reference Matrix identity server. In Sydent versions 2.2.0 ...

EPSS

Процентиль: 51%
0.00281
Низкий

5.3 Medium

CVSS4

4.3 Medium

CVSS3

Дефекты

CWE-20
CWE-400