Описание
Kolab Server 2.0.1, 2.0.2 and development versions pre-2.1-20051215 and earlier, when authenticating users via secure SMTP, stores authentication credentials in plaintext in the postfix.log file, which allows local users to gain privileges.
Ссылки
- PatchVendor Advisory
- PatchVendor Advisory
- PatchVendor Advisory
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2005-12-15_pre2.1 (включая)
Одно из
cpe:2.3:a:kolab:kolab_groupware_server:*:*:*:*:*:*:*:*
cpe:2.3:a:kolab:kolab_groupware_server:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:kolab:kolab_groupware_server:2.0.2:*:*:*:*:*:*:*
EPSS
Процентиль: 26%
0.00093
Низкий
4.6 Medium
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
почти 4 года назад
Kolab Server 2.0.1, 2.0.2 and development versions pre-2.1-20051215 and earlier, when authenticating users via secure SMTP, stores authentication credentials in plaintext in the postfix.log file, which allows local users to gain privileges.
EPSS
Процентиль: 26%
0.00093
Низкий
4.6 Medium
CVSS2
Дефекты
NVD-CWE-Other