CVE-2021-29432
Summary
| CVE | CVE-2021-29432 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-04-15 21:15:00 UTC |
| Updated | 2022-08-03 10:17:00 UTC |
| Description | Sydent is a reference matrix identity server. A malicious user could abuse Sydent to send out arbitrary emails from the Sydent email address. This could be used to construct plausible phishing emails, for example. This issue has been fixed in 4469d1d. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Release Sydent 2.3.0 (2021-04-15) · matrix-org/sydent · GitHub | MISC | github.com | |
| matrix-sydent · PyPI | MISC | pypi.org | |
| Malicious users could control the content of invitation emails · Advisory · matrix-org/sydent · GitHub | CONFIRM | github.com | |
| Randomise multipart boundary, and include mxids in invite email notifs · matrix-org/sydent@4469d1d · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 982746 Python (pip) Security Update for matrix-sydent (GHSA-mh74-4m5g-fcjx)