Email Domain Misconfiguration in Matrix Sydent by Matrix
CVE-2019-11340

5.9MEDIUM

Key Information:

Vendor

Matrix

Status
Vendor
CVE Published:
19 April 2019

What is CVE-2019-11340?

The Matrix Sydent service, specifically the util/emailutils.py module, has a vulnerability that arises from improper handling of registration restrictions tied to email domains. When the allowed_local_3pids option is enabled, the email.utils.parseaddr function can yield unexpected results. This could allow a user to bypass intended restrictions by using email formats that confuse the parser, potentially leading to unwanted registrations with unauthorized domains.

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.