Moderate severityNVD Advisory· Published Apr 15, 2021· Updated Aug 3, 2024
Malicious users could control the content of invitation emails
CVE-2021-29432
Description
Sydent is a reference matrix identity server. A malicious user could abuse Sydent to send out arbitrary emails from the Sydent email address. This could be used to construct plausible phishing emails, for example. This issue has been fixed in 4469d1d.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
matrix-sydentPyPI | < 2.3.0 | 2.3.0 |
Affected products
2- Range: < 2.3.0
Patches
Vulnerability mechanics
References
8- github.com/advisories/GHSA-mh74-4m5g-fcjxghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-29432ghsaADVISORY
- github.com/matrix-org/sydent/commit/4469d1d42b2b1612b70638224c07e19623039c42ghsax_refsource_MISCWEB
- github.com/matrix-org/sydent/releases/tag/v2.3.0ghsax_refsource_MISCWEB
- github.com/matrix-org/sydent/security/advisories/GHSA-mh74-4m5g-fcjxghsax_refsource_CONFIRMWEB
- github.com/pypa/advisory-database/tree/main/vulns/matrix-sydent/PYSEC-2021-23.yamlghsaWEB
- pypi.org/project/matrix-sydentghsaWEB
- pypi.org/project/matrix-sydent/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.