HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2019-11842

CVSS 7.5v3.0pub. 2019-05-09upd. 2024-11-21

An issue was discovered in Matrix Sydent before 1.0.3 and Synapse before 0.99.3.1. Random number generation is mishandled, which makes it easier for attackers to predict a Sydent authentication token or a Synapse random ID.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  • Matrix Sydent

    APP
    Matrix
    < 1.0.3
  • Matrix Synapse

    APP
    Matrix
    < 0.99.3.1
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2023-38686CRITICAL9.3PL ✓same product

Brak weryfikacji certyfikatu SMTP TLS w Matrix Sydent — podatność MITM

CVE-2019-18835CRITICAL9.8PL ✓same product

Matrix Synapse: błąd weryfikacji podpisów w federation API

CVE-2025-30355HIGH7.1same product

Synapse is an open source Matrix homeserver implementation. A malicious server can craft events which, when re...

CVE-2024-52805HIGH8.2same product

Synapse is an open-source Matrix homeserver. In Synapse before 1.120.1, multipart/form-data requests can in ce...

CVE-2024-37302HIGH7.5same product

Synapse is an open-source Matrix homeserver. Synapse versions before 1.106 are vulnerable to a disk fill attac...