SCA: security update for matrix-sydent (GHSA-p6hw-wm59-3g5g)

medium Tenable Cloud Security Plugin ID 417340

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Sydent is an identity server for the Matrix communications protocol. Prior to version 2.5.6, if configured
to send emails using TLS, Sydent does not verify SMTP servers' certificates. This makes Sydent's emails
vulnerable to interception via a man-in-the-middle (MITM) attack. Attackers with privileged access to the
network can intercept room invitations and address confirmation emails. This is patched in Sydent 2.5.6.
When patching, make sure that Sydent trusts the certificate of the server it is connecting to. This should
happen automatically when using properly issued certificates. Those who use self-signed certificates
should make sure to copy their Certification Authority certificate, or their self signed certificate if
using only one, to the trust store of your operating system. As a workaround, one can ensure Sydent's
emails fail to send by setting the configured SMTP server to a loopback or non-routable address under
one's control which does not have a listening SMTP server. (CVE-2023-38686)

See Also

https://github.com/advisories/GHSA-p6hw-wm59-3g5g

Plugin Details

Severity: Medium

ID: 417340

Version: Revision 1.12

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.51

Vendor

Vendor Severity: Critical

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:A/AC:H/Au:N/C:C/I:N/A:N

CVSS Score Source: CVE-2023-38686

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 4.6

Vector: CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 7/31/2023

Vulnerability Publication Date: 7/31/2023

Reference Information

CVE: CVE-2023-38686

cwe: CWE-295