CVE-2019-11340
Matrix Sydent mishandles emails
5.9
MEDIUM
CVSS 3.1
EPSS 0.66%
Description
util/emailutils.py in Matrix Sydent before 1.0.2 mishandles registration restrictions that are based on e-mail domain, if the allowed_local_3pids option is enabled. This occurs because of potentially unwanted behavior in Python, in which an email.utils.parseaddr call on user@bad.example.net@good.example.com returns the user@bad.example.net substring.
How to fix CVE-2019-11340
To remediate CVE-2019-11340, upgrade the affected package to a fixed version below.
- —upgrade to 1.0.2 or later
Is CVE-2019-11340 being exploited?
Low — EPSS is 0.7%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 1.0.2
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.9 | CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N |