Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q9h8-gpw5-c95c

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.9

Описание

Matrix Sydent mishandles emails

util/emailutils.py in Matrix Sydent before 1.0.2 mishandles registration restrictions that are based on e-mail domain, if the allowed_local_3pids option is enabled. This occurs because of potentially unwanted behavior in Python, in which an email.utils.parseaddr call on user@bad.example.net@good.example.com returns the user@bad.example.net substring.

Пакеты

Наименование

matrix-sydent

pip
Затронутые версииВерсия исправления

< 1.0.2

1.0.2

EPSS

Процентиль: 72%
0.00705
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 5.9
nvd
почти 7 лет назад

util/emailutils.py in Matrix Sydent before 1.0.2 mishandles registration restrictions that are based on e-mail domain, if the allowed_local_3pids option is enabled. This occurs because of potentially unwanted behavior in Python, in which an email.utils.parseaddr call on user@bad.example.net@good.example.com returns the user@bad.example.net substring.

CVSS3: 5.9
debian
почти 7 лет назад

util/emailutils.py in Matrix Sydent before 1.0.2 mishandles registrati ...

EPSS

Процентиль: 72%
0.00705
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-20