CVE-2019-11842
published 2019-05-09CVE-2019-11842: An issue was discovered in Matrix Sydent before 1.0.3 and Synapse before 0.99.3.1. Random number generation is mishandled, which makes it easier for attackers…
PriorityP339high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
1.78%
75.8th percentile
An issue was discovered in Matrix Sydent before 1.0.3 and Synapse before 0.99.3.1. Random number generation is mishandled, which makes it easier for attackers to predict a Sydent authentication token or a Synapse random ID.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | matrix-synapse | < matrix-synapse 0.99.2-5 (forky) | matrix-synapse 0.99.2-5 (forky) |
| matrix | sydent | < 1.0.3 | 1.0.3 |
| matrix | synapse | < 0.99.3.1 | 0.99.3.1 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
matrix-synapse vulnerabilities
osv·2023-05-16·CVSS 7.5
CVE-2019-18835 [HIGH] matrix-synapse vulnerabilities
matrix-synapse vulnerabilities
It was discovered that Synapse incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to cause a
denial of service. (CVE-2019-18835, CVE-2018-12291, CVE-2018-10657)
It was discovered that Synapse incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to hijack the
session. (CVE-2019-11842, CVE-2018-12423)
It was discovered that Synapse incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to perform
sp
OSV
matrix-sydent and matrix-synapse Use Cryptographically Weak PRNG
osv·2022-05-24
CVE-2019-11842 [HIGH] matrix-sydent and matrix-synapse Use Cryptographically Weak PRNG
matrix-sydent and matrix-synapse Use Cryptographically Weak PRNG
An issue was discovered in Matrix Sydent before 1.0.3 and Synapse before 0.99.3.1. Random number generation is mishandled, which makes it easier for attackers to predict a Sydent authentication token or a Synapse random ID.
GHSA
matrix-sydent and matrix-synapse Use Cryptographically Weak PRNG
ghsa·2022-05-24
CVE-2019-11842 [HIGH] CWE-338 matrix-sydent and matrix-synapse Use Cryptographically Weak PRNG
matrix-sydent and matrix-synapse Use Cryptographically Weak PRNG
An issue was discovered in Matrix Sydent before 1.0.3 and Synapse before 0.99.3.1. Random number generation is mishandled, which makes it easier for attackers to predict a Sydent authentication token or a Synapse random ID.
OSV
CVE-2019-11842: An issue was discovered in Matrix Sydent before 1
osv·2019-05-09·CVSS 7.5
CVE-2019-11842 [HIGH] CVE-2019-11842: An issue was discovered in Matrix Sydent before 1
An issue was discovered in Matrix Sydent before 1.0.3 and Synapse before 0.99.3.1. Random number generation is mishandled, which makes it easier for attackers to predict a Sydent authentication token or a Synapse random ID.
Ubuntu
Synapse vulnerabilities
vendor_ubuntu·2023-05-16·CVSS 7.5
CVE-2019-5885 [HIGH] Synapse vulnerabilities
Title: Synapse vulnerabilities
Summary: Several security issues were fixed in Synapse.
It was discovered that Synapse incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to cause a
denial of service. (CVE-2019-18835, CVE-2018-12291, CVE-2018-10657)
It was discovered that Synapse incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to hijack the
session. (CVE-2019-11842, CVE-2018-12423)
It was discovered that Synapse incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted
input file, a re
Debian
CVE-2019-11842: matrix-synapse - An issue was discovered in Matrix Sydent before 1.0.3 and Synapse before 0.99.3....
vendor_debian·2019·CVSS 7.5
CVE-2019-11842 [HIGH] CVE-2019-11842: matrix-synapse - An issue was discovered in Matrix Sydent before 1.0.3 and Synapse before 0.99.3....
An issue was discovered in Matrix Sydent before 1.0.3 and Synapse before 0.99.3.1. Random number generation is mishandled, which makes it easier for attackers to predict a Sydent authentication token or a Synapse random ID.
Scope: local
forky: resolved (fixed in 0.99.2-5)
sid: resolved (fixed in 0.99.2-5)
No detection rules found.
No public exploits indexed.
2019-05-09
Published