Predictable Random Number Generation in Matrix Sydent and Synapse

Predictable Random Number Generation in Matrix Sydent and Synapse

CVE-2019-11842 · MEDIUM Severity

AV:N/AC:L/AU:N/C:P/I:N/A:N

An issue was discovered in Matrix Sydent before 1.0.3 and Synapse before 0.99.3.1. Random number generation is mishandled, which makes it easier for attackers to predict a Sydent authentication token or a Synapse random ID.

Learn more about our Web Application Penetration Testing UK.