CVE-2021-29433
published 2021-04-15CVE-2021-29433: Sydent is a reference Matrix identity server. In Sydent versions 2.2.0 and prior, sissing input validation of some parameters on the endpoints used to confirm…
PriorityP420medium4.3CVSS 3.1
AVNACLPRLUINSUCNINAL
EPSS
0.93%
56.5th percentile
Sydent is a reference Matrix identity server. In Sydent versions 2.2.0 and prior, sissing input validation of some parameters on the endpoints used to confirm third-party identifiers could cause excessive use of disk space and memory leading to resource exhaustion. A patch for the vulnerability is in version 2.3.0. No workarounds are known to exist.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| matrix-org | sydent | <= 2.2.0 | — |
| matrix | sydent | < 2.3.0 | 2.3.0 |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Sydent DoS (via resource exhaustion) due to improper input validation
ghsa·2021-04-16
CVE-2021-29433 [MEDIUM] CWE-20 Sydent DoS (via resource exhaustion) due to improper input validation
Sydent DoS (via resource exhaustion) due to improper input validation
### Impact
Missing input validation of some parameters on the endpoints used to confirm third-party identifiers could cause excessive use of disk space and memory leading to resource exhaustion.
### Patches
Fixed by 3175fd3.
### For more information
If you have any questions or comments about this advisory, email us at [email protected].
OSV
Sydent DoS (via resource exhaustion) due to improper input validation
osv·2021-04-16
CVE-2021-29433 [MEDIUM] Sydent DoS (via resource exhaustion) due to improper input validation
Sydent DoS (via resource exhaustion) due to improper input validation
### Impact
Missing input validation of some parameters on the endpoints used to confirm third-party identifiers could cause excessive use of disk space and memory leading to resource exhaustion.
### Patches
Fixed by 3175fd3.
### For more information
If you have any questions or comments about this advisory, email us at [email protected].
OSV
CVE-2021-29433: ### Impact Missing input validation of some parameters on the endpoints used to confirm third-party identifiers could cause excessive use of disk spac
osv·2021-04-15
CVE-2021-29433 CVE-2021-29433: ### Impact Missing input validation of some parameters on the endpoints used to confirm third-party identifiers could cause excessive use of disk spac
### Impact Missing input validation of some parameters on the endpoints used to confirm third-party identifiers could cause excessive use of disk space and memory leading to resource exhaustion. ### Patches Fixed by 3175fd3. ### Workarounds There are no known workarounds. ### References n/a ### For more information If you have any questions or comments about this advisory, email us at [email protected].
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/matrix-org/sydent/commit/3175fd358ebc2c310eab7a3dbf296ce2bd54c1dahttps://github.com/matrix-org/sydent/security/advisories/GHSA-pw4v-gr34-2553https://github.com/matrix-org/sydent/commit/3175fd358ebc2c310eab7a3dbf296ce2bd54c1dahttps://github.com/matrix-org/sydent/security/advisories/GHSA-pw4v-gr34-2553
2021-04-15
Published