SCA: security update for matrix-sydent (GHSA-wmg4-8cp2-hpg9)

high Tenable Cloud Security Plugin ID 420000

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Sydent is a reference Matrix identity server. Sydent does not limit the size of requests it receives from
HTTP clients. A malicious user could send an HTTP request with a very large body, leading to memory
exhaustion and denial of service. Sydent also does not limit response size for requests it makes to remote
Matrix homeservers. A malicious homeserver could return a very large response, again leading to memory
exhaustion and denial of service. This affects any server which accepts registration requests from
untrusted clients. This issue has been patched by releases 89071a1, 0523511, f56eee3. As a workaround
request sizes can be limited in an HTTP reverse-proxy. There are no known workarounds for the problem with
overlarge responses. (CVE-2021-29430)

See Also

https://github.com/advisories/GHSA-wmg4-8cp2-hpg9

Plugin Details

Severity: High

ID: 420000

Version: Revision 1.4

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS Score Source: CVE-2021-29430

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 8.7

Threat Score: 6.6

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 4/19/2021

Vulnerability Publication Date: 4/15/2021

Reference Information

CVE: CVE-2021-29430