CVE-2021-29431High· 7.7▾ TwilightSSRF in Sydent due to missing validation of hostnames
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.4 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
1.2%
Sydent can be induced to send HTTP GET requests to internal systems, due to lack of parameter validation or IP address blacklisting.
It is not possible to exfiltrate data or control request headers, but it might be possible to use the attack to perform an internal port enumeration.
Fixed in 9e57334, 8936925, 3d531ed, 0f00412
A potential workaround would be to use a firewall to ensure that Sydent cannot reach internal HTTP resources.
If you have any questions or comments about this advisory, email us at [email protected].
matrix-sydent < 2.3.0Upgrade to a patched release:
matrix-sydent 2.3.0Connected by shared product, vendor, weakness, or advisory.
CVE-2021-29430High· 7.5Sydent vulnerable to denial of service attack via memory exhaustion
CVE-2021-29433Medium· 4.3Sydent DoS (via resource exhaustion) due to improper input validation
CVE-2021-29432Medium· 5.3Malicious users could abuse Sydent to control the content of invitation emails
CVE-2023-38686Critical· 9.3Sydent does not verify email server certificates
CVE-2019-11842High· 7.5matrix-sydent and matrix-synapse Use Cryptographically Weak PRNG
CVE-2019-11340Medium· 5.9Matrix Sydent mishandles emails