Описание
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. GENURLAUTH-issued tokens can bypass ACLs. Any authenticated user could mint a URLAUTH token (via the GENURLAUTH command) for any mailbox they could name, even without read access on it. This would allow reading mail from mailboxes despite having no granted permissions.
A flaw was found in cyrus-imapd. An authenticated user could exploit this vulnerability by minting a URLAUTH token through the GENURLAUTH command. This allows bypassing Access Control Lists (ACLs), which are rules that control access to mailboxes. Consequently, an attacker could read mail from any mailbox, even without having been granted explicit read permissions.
Отчет
This flaw in cyrus-imapd allows an authenticated attacker to bypass Access Control Lists (ACLs) by minting a URLAUTH token via the GENURLAUTH command. This enables unauthorized reading of mail from any mailbox, even without explicit read permissions, posing a significant risk to data confidentiality in Red Hat deployments utilizing the Cyrus IMAP server.
Меры по смягчению последствий
To reduce the attack surface, restrict network access to the Cyrus IMAP server to only trusted clients and networks by configuring appropriate firewall rules. If the Cyrus IMAP service is not essential, consider disabling it. To disable the cyrus-imapd service, execute sudo systemctl stop cyrus-imapd and sudo systemctl disable cyrus-imapd. Disabling the service will prevent all mail access via IMAP and may require a system restart to fully take effect.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | cyrus-imapd | Fix deferred | ||
| Red Hat Enterprise Linux 6 | cyrus-imapd | Out of support scope | ||
| Red Hat Enterprise Linux 7 | cyrus-imapd | Out of support scope | ||
| Red Hat Enterprise Linux 8 | cyrus-imapd | Fix deferred | ||
| Red Hat Enterprise Linux 9 | cyrus-imapd | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
4.3 Medium
CVSS3
Связанные уязвимости
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. GENURLAUTH-issued tokens can bypass ACLs. Any authenticated user could mint a URLAUTH token (via the GENURLAUTH command) for any mailbox they could name, even without read access on it. This would allow reading mail from mailboxes despite having no granted permissions.
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. GENURLAUTH-issued tokens can bypass ACLs. Any authenticated user could mint a URLAUTH token (via the GENURLAUTH command) for any mailbox they could name, even without read access on it. This would allow reading mail from mailboxes despite having no granted permissions.
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. G ...
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. GENURLAUTH-issued tokens can bypass ACLs. Any authenticated user could mint a URLAUTH token (via the GENURLAUTH command) for any mailbox they could name, even without read access on it. This would allow reading mail from mailboxes despite having no granted permissions.
EPSS
4.3 Medium
CVSS3