CVE-2021-29433: Denial of service (via resource exhaustion) due to improper input validation
Impact
Missing input validation of some parameters on the endpoints used to confirm third-party identifiers could cause excessive use of disk space and memory leading to resource exhaustion.
Patches
Fixed by 3175fd3.
For more information
If you have any questions or comments about this advisory, email us at security@matrix.org.
Other sources
Sydent is a reference Matrix identity server. In Sydent versions 2.2.0 and prior, sissing input validation of some parameters on the endpoints used to confirm third-party identifiers could cause excessive use of disk space and memory leading to resource exhaustion. A patch for the vulnerability is in version 2.3.0. No workarounds are known to exist.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID is CVE-2021-29433.
What is the affected software in this vulnerability?
The affected software is Matrix Sydent version 2.2.0 and prior.
What is the severity of CVE-2021-29433?
The severity of CVE-2021-29433 is medium with a CVSS score of 4.3.
How does CVE-2021-29433 affect the system?
CVE-2021-29433 can cause excessive use of disk space and memory leading to resource exhaustion in Matrix Sydent.
Is there a patch available for CVE-2021-29433?
Yes, a patch for CVE-2021-29433 is available.