cbcvebase.
CVE-2019-11340
published 2019-04-19

CVE-2019-11340: util/emailutils.py in Matrix Sydent before 1.0.2 mishandles registration restrictions that are based on e-mail domain, if the allowed_local_3pids option is…

PriorityP429medium5.9CVSS 3.0
AVNACHPRNUINSUCNIHAN
EPSS
1.86%
76.8th percentile
util/emailutils.py in Matrix Sydent before 1.0.2 mishandles registration restrictions that are based on e-mail domain, if the allowed_local_3pids option is enabled. This occurs because of potentially unwanted behavior in Python, in which an email.utils.parseaddr call on [email protected]@good.example.com returns the [email protected] substring.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debianpython2.7< python2.7 2.7.17~rc1-1 (bullseye)python2.7 2.7.17~rc1-1 (bullseye)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
matrixsydent< 1.0.21.0.2
opensuseleap
opensuseleap
oraclecommunications_operations_monitor
oraclecommunications_operations_monitor4.1 – 4.3
oraclepeoplesoft_enterprise_peopletools
oraclepeoplesoft_enterprise_peopletools
oraclesolaris
oraclezfs_storage_appliance_kit
pythonpython<= 2.7.16
pythonpython3.0.0 – 3.0.1
pythonpython3.1.0 – 3.1.5
pythonpython3.2.0 – 3.2.6
pythonpython3.3.0 – 3.3.7

CVSS provenance

nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.