Junglewise Threat Intelligence

CVE-2021-29432: PYSEC-2021-23 - Sydent is a reference matrix identity server. A malicious user could abuse Sydent to send out arbitrary emails from the Sydent email address

CVE-2021-29432 · Severity: low · CVSS 3.1 · Published 2021-04-15

Technologies: matrix-sydent (PyPI). Vendors: PyPI.

Executive brief

Sydent is a reference matrix identity server. A malicious user could abuse Sydent to send out arbitrary emails from the Sydent email address. This could be used to construct plausible phishing emails, for example. This issue has been fixed in 4469d1d.

Affected products

  • PyPI matrix-sydent

Related threats