CVE-2021-29432
Malicious users could abuse Sydent to control the content of invitation emails
5.3
MEDIUM
CVSS 3.1
EPSS 0.93%
描述
Sydent is a reference matrix identity server. A malicious user could abuse Sydent to send out arbitrary emails from the Sydent email address. This could be used to construct plausible phishing emails, for example. This issue has been fixed in 4469d1d.
如何修補 CVE-2021-29432
要修補 CVE-2021-29432,請將受影響套件升級到下列已修補版本。
- —升級至 2.3.0 或更新版本
- —升級至 4469d1d42b2b1612b70638224c07e19623039c42 或更新版本
CVE-2021-29432 正在被利用嗎?
低 — EPSS 為 0.9%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 2.3.0
- from 0, < 4469d1d42b2b1612b70638224c07e19623039c42 | from 0, < 2.3.0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
| osv | CVSS 3.1 | MEDIUM5.3 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |