CVE-2021-29432

MEDIUM

Matrix Sydent < 2.3.0 - Improper Input Validation

Title source: rule
STIX 2.1

Description

Sydent is a reference matrix identity server. A malicious user could abuse Sydent to send out arbitrary emails from the Sydent email address. This could be used to construct plausible phishing emails, for example. This issue has been fixed in 4469d1d.

References (4)

Core 4
Core References
Product, Third Party Advisory x_refsource_misc
https://pypi.org/project/matrix-sydent/
Release Notes, Third Party Advisory x_refsource_misc
https://github.com/matrix-org/sydent/releases/tag/v2.3.0

Scores

CVSS v3 5.3
EPSS 0.0025
EPSS Percentile 48.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-20
Status published
Products (2)
matrix/sydent < 2.3.0
pypi/matrix-sydent 0 - 2.3.0PyPI
Published Apr 15, 2021
Tracked Since Feb 18, 2026