Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-18928

Опубликовано: 14 нояб. 2019
Источник: redhat
CVSS3: 7.4
EPSS Низкий

Описание

Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection.

Отчет

If HTTP is enabled (e.g. RSS, CalDAV), cyrus-imapd does not properly authenticate a HTTP request coming through a connection that has been previously authenticated. Usually, this is not a problem, as each user will have their own connection and a breach of security boundaries would not be possible. An exception to this rule is if the cyrus-imapd HTTP service is behind a proxy, for example a reverse caching proxy, and said proxy reuses the same connection to cyrus-imapd for multiple requests.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5cyrus-imapdNot affected
Red Hat Enterprise Linux 6cyrus-imapdNot affected
Red Hat Enterprise Linux 7cyrus-imapdNot affected
Red Hat Enterprise Linux 8cyrus-imapdFixedRHSA-2020:465504.11.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-287
https://bugzilla.redhat.com/show_bug.cgi?id=1775177cyrus-imapd: privilege escalation in HTTP request

EPSS

Процентиль: 65%
0.005
Низкий

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 6 лет назад

Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection.

CVSS3: 9.8
nvd
около 6 лет назад

Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection.

CVSS3: 9.8
debian
около 6 лет назад

Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege ...

CVSS3: 9.8
github
больше 3 лет назад

Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection.

oracle-oval
около 5 лет назад

ELSA-2020-4655: cyrus-imapd security update (MODERATE)

EPSS

Процентиль: 65%
0.005
Низкий

7.4 High

CVSS3