util/emailutils.py in Matrix Sydent before 1.0.2 mishandles registration restrictions that are based on e-mail domain, if the allowed_local_3pids option is enabled. This occurs because of potentially unwanted behavior in Python, in which an email.utils.parseaddr call on user@bad.example.net@good.example.com returns the user@bad.example.net substring.
Advisories
Source ID Title
Debian DLA Debian DLA DLA-2280-1 python3.5 security update
EUVD EUVD EUVD-2022-4932 util/emailutils.py in Matrix Sydent before 1.0.2 mishandles registration restrictions that are based on e-mail domain, if the allowed_local_3pids option is enabled. This occurs because of potentially unwanted behavior in Python, in which an email.utils.parseaddr call on user@bad.example.net@good.example.com returns the user@bad.example.net substring.
Github GHSA Github GHSA GHSA-q9h8-gpw5-c95c Matrix Sydent mishandles emails
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T22:48:09.226Z

Reserved: 2019-04-19T00:00:00

Link: CVE-2019-11340

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-04-19T14:29:00.417

Modified: 2024-11-21T04:20:54.877

Link: CVE-2019-11340

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses