Sydent does not verify email server certificates · Advisory · matrix-org/sydent · GitHub

Sydent does not verify email server certificates · Advisory · matrix-org/sydent · GitHub

Impact If configured to send emails using TLS, Sydent does not verify SMTP servers' certificates. This makes Sydent's emails vulnerable to interception via a man-in-the-middle (MITM) attack. Attackers with privileged access to the network can intercept room invitations and address...
Sydent does not verify email server certificates · CVE-2023-38686 · GitHub Advisory Database · GitHub

Sydent does not verify email server certificates · CVE-2023-38686 · GitHub Advisory Database · GitHub

Impact If configured to send emails using TLS, Sydent does not verify SMTP servers' certificates. This makes Sydent's emails vulnerable to interception via a man-in-the-middle (MITM) attack. Attackers with privileged access to the network can intercept room invitations and address...