CVE-2021-29432

MEDIUM

matrix-sydent < 2.3.0 - Arbitrary Email Spoofing via Identity Server

Title source: llm
STIX 2.1

Description

Sydent is a reference matrix identity server. A malicious user could abuse Sydent to send out arbitrary emails from the Sydent email address. This could be used to construct plausible phishing emails, for example. This issue has been fixed in 4469d1d.

References (4)

Core 4
Core References
Product, Third Party Advisory x_refsource_misc
https://pypi.org/project/matrix-sydent/
Release Notes, Third Party Advisory x_refsource_misc
https://github.com/matrix-org/sydent/releases/tag/v2.3.0

Scores

CVSS v3 5.3
EPSS 0.0093
EPSS Percentile 56.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-20
Status published
Products (2)
matrix/sydent < 2.3.0
pypi/matrix-sydent 0 - 2.3.0PyPI
Published Apr 15, 2021
Tracked Since Feb 18, 2026