CVE-2021-29432
published 2021-04-15CVE-2021-29432: Sydent is a reference matrix identity server. A malicious user could abuse Sydent to send out arbitrary emails from the Sydent email address. This could be…
PriorityP428medium5.7CVSS 3.1
AVNACLPRLUIRSUCNIHAN
EPSS
0.93%
56.8th percentile
Sydent is a reference matrix identity server. A malicious user could abuse Sydent to send out arbitrary emails from the Sydent email address. This could be used to construct plausible phishing emails, for example. This issue has been fixed in 4469d1d.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| matrix-org | sydent | < 2.3.0 | 2.3.0 |
| matrix | sydent | < 2.3.0 | 2.3.0 |
CVSS provenance
nvdv3.15.7MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Malicious users could abuse Sydent to control the content of invitation emails
osv·2021-04-19
CVE-2021-29432 [MEDIUM] Malicious users could abuse Sydent to control the content of invitation emails
Malicious users could abuse Sydent to control the content of invitation emails
### Impact
A malicious user could abuse Sydent to send out arbitrary emails from the Sydent email address. This could be used to construct plausible phishing emails, for example.
### Patches
Fixed in 4469d1d, 6b405a8, 65a6e91.
Note that these patches include changes to the *default* email templates. If these templates have been locally modified, they must also be updated.
### For more information
If you have any questions or comments about this advisory, email us at [email protected].
GHSA
Malicious users could abuse Sydent to control the content of invitation emails
ghsa·2021-04-19
CVE-2021-29432 [MEDIUM] CWE-20 Malicious users could abuse Sydent to control the content of invitation emails
Malicious users could abuse Sydent to control the content of invitation emails
### Impact
A malicious user could abuse Sydent to send out arbitrary emails from the Sydent email address. This could be used to construct plausible phishing emails, for example.
### Patches
Fixed in 4469d1d, 6b405a8, 65a6e91.
Note that these patches include changes to the *default* email templates. If these templates have been locally modified, they must also be updated.
### For more information
If you have any questions or comments about this advisory, email us at [email protected].
OSV
CVE-2021-29432: Sydent is a reference matrix identity server
osv·2021-04-15
CVE-2021-29432 CVE-2021-29432: Sydent is a reference matrix identity server
Sydent is a reference matrix identity server. A malicious user could abuse Sydent to send out arbitrary emails from the Sydent email address. This could be used to construct plausible phishing emails, for example. This issue has been fixed in 4469d1d.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/matrix-org/sydent/commit/4469d1d42b2b1612b70638224c07e19623039c42https://github.com/matrix-org/sydent/releases/tag/v2.3.0https://github.com/matrix-org/sydent/security/advisories/GHSA-mh74-4m5g-fcjxhttps://pypi.org/project/matrix-sydent/https://github.com/matrix-org/sydent/commit/4469d1d42b2b1612b70638224c07e19623039c42https://github.com/matrix-org/sydent/releases/tag/v2.3.0https://github.com/matrix-org/sydent/security/advisories/GHSA-mh74-4m5g-fcjxhttps://pypi.org/project/matrix-sydent/
2021-04-15
Published