Логотип exploitDog
bind:CVE-2021-21394
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-21394

Количество 4

Количество 4

ubuntu логотип

CVE-2021-21394

почти 5 лет назад

Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.28.0 Synapse is missing input validation of some parameters on the endpoints used to confirm third-party identifiers could cause excessive use of disk space and memory leading to resource exhaustion. Note that the groups feature is not part of the Matrix specification and the chosen maximum lengths are arbitrary. Not all clients might abide by them. Refer to referenced GitHub security advisory for additional details including workarounds.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2021-21394

почти 5 лет назад

Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.28.0 Synapse is missing input validation of some parameters on the endpoints used to confirm third-party identifiers could cause excessive use of disk space and memory leading to resource exhaustion. Note that the groups feature is not part of the Matrix specification and the chosen maximum lengths are arbitrary. Not all clients might abide by them. Refer to referenced GitHub security advisory for additional details including workarounds.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2021-21394

почти 5 лет назад

Synapse is a Matrix reference homeserver written in python (pypi packa ...

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-w9fg-xffh-p362

почти 5 лет назад

Denial of service (via resource exhaustion) due to improper input validation on third-party identifier endpoints

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2021-21394

Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.28.0 Synapse is missing input validation of some parameters on the endpoints used to confirm third-party identifiers could cause excessive use of disk space and memory leading to resource exhaustion. Note that the groups feature is not part of the Matrix specification and the chosen maximum lengths are arbitrary. Not all clients might abide by them. Refer to referenced GitHub security advisory for additional details including workarounds.

CVSS3: 5.3
1%
Низкий
почти 5 лет назад
nvd логотип
CVE-2021-21394

Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.28.0 Synapse is missing input validation of some parameters on the endpoints used to confirm third-party identifiers could cause excessive use of disk space and memory leading to resource exhaustion. Note that the groups feature is not part of the Matrix specification and the chosen maximum lengths are arbitrary. Not all clients might abide by them. Refer to referenced GitHub security advisory for additional details including workarounds.

CVSS3: 5.3
1%
Низкий
почти 5 лет назад
debian логотип
CVE-2021-21394

Synapse is a Matrix reference homeserver written in python (pypi packa ...

CVSS3: 5.3
1%
Низкий
почти 5 лет назад
github логотип
GHSA-w9fg-xffh-p362

Denial of service (via resource exhaustion) due to improper input validation on third-party identifier endpoints

CVSS3: 5.3
1%
Низкий
почти 5 лет назад

Уязвимостей на страницу