Package impact

python PyPI / matrix-sydent

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2023-38686 unknown 3y ago Sydent is an identity server for the Matrix communications protocol. Prior to version 2.5.6, if configured to send emails using TLS, Sydent does not verify SMTP servers' certificates. This makes Syd… python
CVE-2019-11842 unknown 4y ago An issue was discovered in Matrix Sydent before 1.0.3 and Synapse before 0.99.3.1. Random number generation is mishandled, which makes it easier for attackers to predict a Sydent authentication token… debianpython
CVE-2019-11340 unknown 4y ago Matrix Sydent mishandles emails python
CVE-2021-29432 unknown 5y ago Sydent is a reference matrix identity server. A malicious user could abuse Sydent to send out arbitrary emails from the Sydent email address. This could be used to construct plausible phishing emails… python
CVE-2021-29431 unknown 5y ago Sydent is a reference Matrix identity server. Sydent can be induced to send HTTP GET requests to internal systems, due to lack of parameter validation or IP address blacklisting. It is not possible t… python
CVE-2021-29430 unknown 5y ago Sydent is a reference Matrix identity server. Sydent does not limit the size of requests it receives from HTTP clients. A malicious user could send an HTTP request with a very large body, leading to … python
CVE-2021-29433 unknown 5y ago ### Impact Missing input validation of some parameters on the endpoints used to confirm third-party identifiers could cause excessive use of disk space and memory leading to resource exhaustion. ### … python