An issue was discovered in Matrix Sydent before 1.0.3 and Synapse before 0.99.3.1. Random number generation is mishandled, which makes it easier for attackers to predict a Sydent authentication token or a Synapse random ID.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-0082 | An issue was discovered in Matrix Sydent before 1.0.3 and Synapse before 0.99.3.1. Random number generation is mishandled, which makes it easier for attackers to predict a Sydent authentication token or a Synapse random ID. |
Github GHSA |
GHSA-gwf7-vfjf-wf6x | matrix-sydent and matrix-synapse Use Cryptographically Weak PRNG |
Ubuntu USN |
USN-6076-1 | Synapse vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T23:03:32.882Z
Reserved: 2019-05-09T00:00:00
Link: CVE-2019-11842
No data.
Status : Modified
Published: 2019-05-09T18:29:07.197
Modified: 2024-11-21T04:21:52.673
Link: CVE-2019-11842
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA
Ubuntu USN