Medium severity5.3NVD Advisory· Published Apr 15, 2021· Updated Jun 17, 2026
CVE-2021-29432
CVE-2021-29432
Description
Sydent is a reference matrix identity server. A malicious user could abuse Sydent to send out arbitrary emails from the Sydent email address. This could be used to construct plausible phishing emails, for example. This issue has been fixed in 4469d1d.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
matrix-sydentPyPI | < 2.3.0 | 2.3.0 |
Affected products
3cpe:2.3:a:matrix:sydent:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:matrix:sydent:*:*:*:*:*:*:*:*range: <2.3.0
- (no CPE)range: < 2.3.0
Patches
Vulnerability mechanics
References
8- github.com/matrix-org/sydent/commit/4469d1d42b2b1612b70638224c07e19623039c42nvdPatchThird Party AdvisoryWEB
- github.com/matrix-org/sydent/security/advisories/GHSA-mh74-4m5g-fcjxnvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-mh74-4m5g-fcjxghsaADVISORY
- github.com/matrix-org/sydent/releases/tag/v2.3.0nvdRelease NotesThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2021-29432ghsaADVISORY
- pypi.org/project/matrix-sydent/nvdProductThird Party Advisory
- github.com/pypa/advisory-database/tree/main/vulns/matrix-sydent/PYSEC-2021-23.yamlghsaWEB
- pypi.org/project/matrix-sydentghsaWEB
News mentions
0No linked articles in our index yet.