CVE-2019-11842

unknown
Published 2022-05-24 · Modified 2023-11-08
CVSS v3
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v2
VIR risk

Description

An issue was discovered in Matrix Sydent before 1.0.3 and Synapse before 0.99.3.1. Random number generation is mishandled, which makes it easier for attackers to predict a Sydent authentication token or a Synapse random ID.

Predictions

Exploit likelihood
30%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2019-11842

OS impact

OSVersionStatusFixed in
debian debianforkyfixed0.99.2-5
debian debiansidfixed0.99.2-5

Package impact

EcosystemPackageVulnerableFixed
python PyPImatrix-sydent<1.0.31.0.3
python PyPImatrix-synapse<0.99.3.10.99.3.1

References

Verify integrity in audit chain (admin only). AS-IS.