CVE-2021-29432

Sydent is a reference matrix identity server. A malicious user could abuse Sydent to send out arbitrary emails from the Sydent email address. This could be used to construct plausible phishing emails, for example. This issue has been fixed in 4469d1d.
Configurations

Configuration 1 (hide)

cpe:2.3:a:matrix:sydent:*:*:*:*:*:*:*:*

History

21 Nov 2024, 06:01

Type Values Removed Values Added
CVSS v2 : 3.5
v3 : 5.7
v2 : 3.5
v3 : 5.3
References () https://github.com/matrix-org/sydent/commit/4469d1d42b2b1612b70638224c07e19623039c42 - Patch, Third Party Advisory () https://github.com/matrix-org/sydent/commit/4469d1d42b2b1612b70638224c07e19623039c42 - Patch, Third Party Advisory
References () https://github.com/matrix-org/sydent/releases/tag/v2.3.0 - Release Notes, Third Party Advisory () https://github.com/matrix-org/sydent/releases/tag/v2.3.0 - Release Notes, Third Party Advisory
References () https://github.com/matrix-org/sydent/security/advisories/GHSA-mh74-4m5g-fcjx - Patch, Third Party Advisory () https://github.com/matrix-org/sydent/security/advisories/GHSA-mh74-4m5g-fcjx - Patch, Third Party Advisory
References () https://pypi.org/project/matrix-sydent/ - Product, Third Party Advisory () https://pypi.org/project/matrix-sydent/ - Product, Third Party Advisory

Information

Published : 2021-04-15 21:15

Updated : 2024-11-21 06:01


NVD link : CVE-2021-29432

Mitre link : CVE-2021-29432

CVE.ORG link : CVE-2021-29432


JSON object : View

Products Affected

matrix

  • sydent
CWE
CWE-20

Improper Input Validation

NVD-CWE-noinfo