Описание
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. LISTRIGHTS os not limited to users with admin access. An authenticated user could call IMAP LISTRIGHTS against any mailbox they could name and learn what principals had what access to it. (This action should have been restricted to users with admin access on the target mailbox.)
A flaw was found in Cyrus IMAP (cyrus-imapd). An authenticated user can exploit this vulnerability by using the IMAP LISTRIGHTS command. This allows the user to learn the access permissions of any mailbox they can name, which should be restricted to administrators. This leads to unauthorized information disclosure regarding mailbox access controls.
Отчет
This Moderate-impact information disclosure flaw in Cyrus IMAP allows an authenticated user to enumerate mailbox access rights via the LISTRIGHTS command. While requiring prior authentication, this bypasses intended administrative restrictions, potentially exposing sensitive access control configurations within a Red Hat deployment. The impact is limited to information disclosure and does not grant further privileges or data modification.
Меры по смягчению последствий
To mitigate this issue, restrict network access to the Cyrus IMAP service to only trusted clients and networks. This can be achieved by configuring firewall rules to limit inbound connections to the IMAP port (typically 143 for IMAP and 993 for IMAPS) on the server hosting cyrus-imapd. Additionally, ensure that only necessary users have authenticated access to the IMAP server.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | cyrus-imapd | Fix deferred | ||
| Red Hat Enterprise Linux 6 | cyrus-imapd | Out of support scope | ||
| Red Hat Enterprise Linux 7 | cyrus-imapd | Out of support scope | ||
| Red Hat Enterprise Linux 8 | cyrus-imapd | Fix deferred | ||
| Red Hat Enterprise Linux 9 | cyrus-imapd | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
4.3 Medium
CVSS3
Связанные уязвимости
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. LISTRIGHTS os not limited to users with admin access. An authenticated user could call IMAP LISTRIGHTS against any mailbox they could name and learn what principals had what access to it. (This action should have been restricted to users with admin access on the target mailbox.)
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. LISTRIGHTS os not limited to users with admin access. An authenticated user could call IMAP LISTRIGHTS against any mailbox they could name and learn what principals had what access to it. (This action should have been restricted to users with admin access on the target mailbox.)
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. L ...
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. LISTRIGHTS os not limited to users with admin access. An authenticated user could call IMAP LISTRIGHTS against any mailbox they could name and learn what principals had what access to it. (This action should have been restricted to users with admin access on the target mailbox.)
EPSS
4.3 Medium
CVSS3