Sync-in

Server

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.29%
  • Veröffentlicht 21.09.2026 20:31:46
  • Zuletzt bearbeitet 30.09.2026 17:32:07

Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Versions prior to 2.4.1 contain an observable timing discrepancy in the login endpoint because authentication attempts for nonexistent accounts return wi...

  • EPSS 0.29%
  • Veröffentlicht 21.09.2026 20:28:53
  • Zuletzt bearbeitet 24.09.2026 21:25:27

Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0, the sync diff endpoint compiles a user-supplied string into a `RegExp` with no complexity validation. A catastrophic-backtracking...

  • EPSS 0.23%
  • Veröffentlicht 21.09.2026 20:01:56
  • Zuletzt bearbeitet 24.09.2026 23:17:12

Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0, `POST /api/auth/token` authenticates with username and password only, then calls `getTokens()`, which returns full access and ref...

  • EPSS 0.18%
  • Veröffentlicht 21.09.2026 19:50:14
  • Zuletzt bearbeitet 24.09.2026 23:17:12

Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0, `POST /api/app/sync/register` accepts credentials and a TOTP code to register a desktop sync client. On a failed TOTP, `SyncClien...

  • EPSS 0.22%
  • Veröffentlicht 16.06.2026 14:31:30
  • Zuletzt bearbeitet 16.06.2026 19:16:55

Sync-in Server is a secure, open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.3.0, the private IP blocklist regex used in the URL download feature does not match IPv4-mapped IPv6 addresses (e.g. ::ffff:127...

  • EPSS 0.33%
  • Veröffentlicht 08.05.2026 13:00:54
  • Zuletzt bearbeitet 12.05.2026 15:00:33

Sync-in Server is a secure, open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.2.0, the /api/auth/login endpoint contains a logic flaw that allows unauthenticated remote attackers to enumerate valid usernam...