Lucene search

K
osvGoogleOSV:GHSA-Q9H8-GPW5-C95C
HistoryMay 24, 2022 - 4:43 p.m.

Matrix Sydent mishandles emails

2022-05-2416:43:57
Google
osv.dev
11

0.002 Low

EPSS

Percentile

55.3%

util/emailutils.py in Matrix Sydent before 1.0.2 mishandles registration restrictions that are based on e-mail domain, if the allowed_local_3pids option is enabled. This occurs because of potentially unwanted behavior in Python, in which an email.utils.parseaddr call on [email protected]@good.example.com returns the [email protected] substring.