CVE-2021-29431
published 2021-04-15CVE-2021-29431: Sydent is a reference Matrix identity server. Sydent can be induced to send HTTP GET requests to internal systems, due to lack of parameter validation or IP…
PriorityP338medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
1.19%
64.8th percentile
Sydent is a reference Matrix identity server. Sydent can be induced to send HTTP GET requests to internal systems, due to lack of parameter validation or IP address blacklisting. It is not possible to exfiltrate data or control request headers, but it might be possible to use the attack to perform an internal port enumeration. This issue has been addressed in in 9e57334, 8936925, 3d531ed, 0f00412. A potential workaround would be to use a firewall to ensure that Sydent cannot reach internal HTTP resources.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| matrix-org | sydent | < 2.3.0 | 2.3.0 |
| matrix | sydent | < 2.3.0 | 2.3.0 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
SSRF in Sydent due to missing validation of hostnames
osv·2021-04-19
CVE-2021-29431 [MEDIUM] SSRF in Sydent due to missing validation of hostnames
SSRF in Sydent due to missing validation of hostnames
### Impact
Sydent can be induced to send HTTP GET requests to internal systems, due to lack of parameter validation or IP address blacklisting.
It is not possible to exfiltrate data or control request headers, but it might be possible to use the attack to perform an internal port enumeration.
### Patches
Fixed in 9e57334, 8936925, 3d531ed, 0f00412
### Workarounds
A potential workaround would be to use a firewall to ensure that Sydent cannot reach internal HTTP resources.
### For more information
If you have any questions or comments about this advisory, email us at [email protected].
GHSA
SSRF in Sydent due to missing validation of hostnames
ghsa·2021-04-19
CVE-2021-29431 [MEDIUM] CWE-20 SSRF in Sydent due to missing validation of hostnames
SSRF in Sydent due to missing validation of hostnames
### Impact
Sydent can be induced to send HTTP GET requests to internal systems, due to lack of parameter validation or IP address blacklisting.
It is not possible to exfiltrate data or control request headers, but it might be possible to use the attack to perform an internal port enumeration.
### Patches
Fixed in 9e57334, 8936925, 3d531ed, 0f00412
### Workarounds
A potential workaround would be to use a firewall to ensure that Sydent cannot reach internal HTTP resources.
### For more information
If you have any questions or comments about this advisory, email us at [email protected].
OSV
CVE-2021-29431: Sydent is a reference Matrix identity server
osv·2021-04-15
CVE-2021-29431 CVE-2021-29431: Sydent is a reference Matrix identity server
Sydent is a reference Matrix identity server. Sydent can be induced to send HTTP GET requests to internal systems, due to lack of parameter validation or IP address blacklisting. It is not possible to exfiltrate data or control request headers, but it might be possible to use the attack to perform an internal port enumeration. This issue has been addressed in in 9e57334, 8936925, 3d531ed, 0f00412. A potential workaround would be to use a firewall to ensure that Sydent cannot reach internal HTTP resources.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/matrix-org/sydent/commit/0f00412017f25619bc36c264b29ea96808bf310ahttps://github.com/matrix-org/sydent/commit/3d531ed50d2fd41ac387f36d44d3fb2c62dd22d3https://github.com/matrix-org/sydent/commit/8936925f561b0c352c2fa922d5097d7245aad00ahttps://github.com/matrix-org/sydent/commit/9e573348d81df8191bbe8c266c01999c9d57cd5fhttps://github.com/matrix-org/sydent/releases/tag/v2.3.0https://github.com/matrix-org/sydent/security/advisories/GHSA-9jhm-8m8c-c3f4https://pypi.org/project/matrix-sydent/https://github.com/matrix-org/sydent/commit/0f00412017f25619bc36c264b29ea96808bf310ahttps://github.com/matrix-org/sydent/commit/3d531ed50d2fd41ac387f36d44d3fb2c62dd22d3https://github.com/matrix-org/sydent/commit/8936925f561b0c352c2fa922d5097d7245aad00ahttps://github.com/matrix-org/sydent/commit/9e573348d81df8191bbe8c266c01999c9d57cd5fhttps://github.com/matrix-org/sydent/releases/tag/v2.3.0https://github.com/matrix-org/sydent/security/advisories/GHSA-9jhm-8m8c-c3f4https://pypi.org/project/matrix-sydent/
2021-04-15
Published