CVE-2021-29433

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
15/04/2021
Last modified:
02/08/2022

Description

Sydent is a reference Matrix identity server. In Sydent versions 2.2.0 and prior, sissing input validation of some parameters on the endpoints used to confirm third-party identifiers could cause excessive use of disk space and memory leading to resource exhaustion. A patch for the vulnerability is in version 2.3.0. No workarounds are known to exist.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:matrix:sydent:*:*:*:*:*:*:*:* 2.3.0 (excluding)