Malicious users could control the content of invitation emails
CVE-2021-29432

5.3MEDIUM

Key Information:

Vendor

Matrix-org

Status
Vendor
CVE Published:
15 April 2021

What is CVE-2021-29432?

Sydent is a reference matrix identity server. A malicious user could abuse Sydent to send out arbitrary emails from the Sydent email address. This could be used to construct plausible phishing emails, for example. This issue has been fixed in 4469d1d.

Affected Version(s)

sydent < 2.3.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.