CVE-2021-29433Medium· 4.3▾ SunlitSydent DoS (via resource exhaustion) due to improper input validation
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.9%
Missing input validation of some parameters on the endpoints used to confirm third-party identifiers could cause excessive use of disk space and memory leading to resource exhaustion.
Fixed by 3175fd3.
If you have any questions or comments about this advisory, email us at [email protected].
matrix-sydent < 2.3.0Upgrade to a patched release:
matrix-sydent 2.3.0Connected by shared product, vendor, weakness, or advisory.
CVE-2021-29430High· 7.5Sydent vulnerable to denial of service attack via memory exhaustion
CVE-2021-29431High· 7.7SSRF in Sydent due to missing validation of hostnames
CVE-2023-38686Critical· 9.3Sydent does not verify email server certificates
CVE-2021-29432Medium· 5.3Malicious users could abuse Sydent to control the content of invitation emails
CVE-2019-11842High· 7.5matrix-sydent and matrix-synapse Use Cryptographically Weak PRNG
CVE-2019-11340Medium· 5.9Matrix Sydent mishandles emails