CVE-2021-29432

Sydent is a reference matrix identity server. A malicious user could abuse Sydent to send out arbitrary emails from the Sydent email address. This could be used to construct plausible phishing emails, for example. This issue has been fixed in 4469d1d.
Configurations

Configuration 1 (hide)

cpe:2.3:a:matrix:sydent:*:*:*:*:*:*:*:*

History

03 Aug 2022, 10:17

Type Values Removed Values Added
CWE CWE-20 NVD-CWE-noinfo

22 Apr 2021, 15:25

Type Values Removed Values Added
References (CONFIRM) https://github.com/matrix-org/sydent/security/advisories/GHSA-mh74-4m5g-fcjx - (CONFIRM) https://github.com/matrix-org/sydent/security/advisories/GHSA-mh74-4m5g-fcjx - Patch, Third Party Advisory
References (MISC) https://github.com/matrix-org/sydent/commit/4469d1d42b2b1612b70638224c07e19623039c42 - (MISC) https://github.com/matrix-org/sydent/commit/4469d1d42b2b1612b70638224c07e19623039c42 - Patch, Third Party Advisory
References (MISC) https://github.com/matrix-org/sydent/releases/tag/v2.3.0 - (MISC) https://github.com/matrix-org/sydent/releases/tag/v2.3.0 - Release Notes, Third Party Advisory
References (MISC) https://pypi.org/project/matrix-sydent/ - (MISC) https://pypi.org/project/matrix-sydent/ - Product, Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 3.5
v3 : 5.7
CPE cpe:2.3:a:matrix:sydent:*:*:*:*:*:*:*:*

15 Apr 2021, 21:18

Type Values Removed Values Added
New CVE

Information

Published : 2021-04-15 21:15

Updated : 2023-12-10 13:55


NVD link : CVE-2021-29432

Mitre link : CVE-2021-29432

CVE.ORG link : CVE-2021-29432


JSON object : View

Products Affected

matrix

  • sydent
CWE
NVD-CWE-noinfo CWE-20

Improper Input Validation