First published: Thu May 09 2019(Updated: )
An issue was discovered in Matrix Sydent before 1.0.3 and Synapse before 0.99.3.1. Random number generation is mishandled, which makes it easier for attackers to predict a Sydent authentication token or a Synapse random ID.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Matrix Sydent | <1.0.3 | |
Matrix Synapse | <0.99.3.1 | |
pip/matrix-synapse | <0.99.3.1 | 0.99.3.1 |
pip/matrix-sydent | <1.0.3 | 1.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11842 is an issue in Matrix Sydent before 1.0.3 and Synapse before 0.99.3.1 where random number generation is mishandled, making it easier for attackers to predict a Sydent authentication token or a Synapse random ID.
Matrix Sydent versions up to and excluding 1.0.3 and Matrix Synapse versions up to and excluding 0.99.3.1 are affected by CVE-2019-11842.
The severity of CVE-2019-11842 is high with a CVSS score of 7.5.
Attackers can exploit CVE-2019-11842 by predicting a Sydent authentication token or a Synapse random ID due to mishandled random number generation.
Yes, a fix for CVE-2019-11842 is available. Matrix Sydent version 1.0.3 and Matrix Synapse version 0.99.3.1 and above address this vulnerability.