CVE-2019-11842: Weak RNG
An issue was discovered in Matrix Sydent before 1.0.3 and Synapse before 0.99.3.1. Random number generation is mishandled, which makes it easier for attackers to predict a Sydent authentication token or a Synapse random ID.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability CVE-2019-11842?
CVE-2019-11842 is an issue in Matrix Sydent before 1.0.3 and Synapse before 0.99.3.1 where random number generation is mishandled, making it easier for attackers to predict a Sydent authentication token or a Synapse random ID.
Which software is affected by CVE-2019-11842?
Matrix Sydent versions up to and excluding 1.0.3 and Matrix Synapse versions up to and excluding 0.99.3.1 are affected by CVE-2019-11842.
What is the severity of CVE-2019-11842?
The severity of CVE-2019-11842 is high with a CVSS score of 7.5.
How can attackers exploit CVE-2019-11842?
Attackers can exploit CVE-2019-11842 by predicting a Sydent authentication token or a Synapse random ID due to mishandled random number generation.
Is there a fix available for CVE-2019-11842?
Yes, a fix for CVE-2019-11842 is available. Matrix Sydent version 1.0.3 and Matrix Synapse version 0.99.3.1 and above address this vulnerability.