Matrix Sydent是英国Matrix.org基金会的一款Matrix身份验证服务器API的实现。 Sydent 存在安全漏洞,该漏洞源于缺乏参数验证或IP地址黑名单,可能导致Sydent向内部系统发送HTTP GET请求。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| matrix-org | sydent | < 2.3.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-29430 | 7.5 HIGH | Denial of service attack via memory exhaustion |
| CVE-2021-29432 | 5.3 MEDIUM | Malicious users could control the content of invitation emails |
| CVE-2021-29433 | 4.3 MEDIUM | Denial of service (via resource exhaustion) due to improper input validation |
No comments yet