Описание
Sydent is a reference Matrix identity server. In Sydent versions 2.2.0 and prior, sissing input validation of some parameters on the endpoints used to confirm third-party identifiers could cause excessive use of disk space and memory leading to resource exhaustion. A patch for the vulnerability is in version 2.3.0. No workarounds are known to exist.
Ссылки
- PatchThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.3.0 (исключая)
cpe:2.3:a:matrix:sydent:*:*:*:*:*:*:*:*
EPSS
Процентиль: 51%
0.00281
Низкий
4.3 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-20
CWE-400
Связанные уязвимости
CVSS3: 4.3
debian
почти 5 лет назад
Sydent is a reference Matrix identity server. In Sydent versions 2.2.0 ...
CVSS3: 4.3
github
почти 5 лет назад
Sydent DoS (via resource exhaustion) due to improper input validation
EPSS
Процентиль: 51%
0.00281
Низкий
4.3 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-20
CWE-400