Описание
An issue was discovered in Cyrus IMAP before 3.12.4. JMAP snooze bypasses the destination-mailbox ACL. An authenticated user with insert permissions on another user's snoozed mailbox could cause insertion of mail to that user's inbox, or any other of their mailboxes whose id was known to the user, despite having no insert permissions to the target mailbox.
A flaw was found in cyrus-imapd. An authenticated user with insert permissions on another user's snoozed mailbox could bypass access controls. This allows the user to insert mail into the target user's inbox or other known mailboxes, even without explicit insert permissions for those mailboxes. This vulnerability leads to unauthorized modification of another user's mail data.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | cyrus-imapd | Fix deferred | ||
| Red Hat Enterprise Linux 6 | cyrus-imapd | Out of support scope | ||
| Red Hat Enterprise Linux 7 | cyrus-imapd | Fix deferred | ||
| Red Hat Enterprise Linux 8 | cyrus-imapd | Fix deferred | ||
| Red Hat Enterprise Linux 9 | cyrus-imapd | Fix deferred |
Показывать по
Дополнительная информация
Статус:
4.3 Medium
CVSS3
Связанные уязвимости
An issue was discovered in Cyrus IMAP before 3.12.4. JMAP snooze bypasses the destination-mailbox ACL. An authenticated user with insert permissions on another user's snoozed mailbox could cause insertion of mail to that user's inbox, or any other of their mailboxes whose id was known to the user, despite having no insert permissions to the target mailbox.
An issue was discovered in Cyrus IMAP before 3.12.4. JMAP snooze bypasses the destination-mailbox ACL. An authenticated user with insert permissions on another user's snoozed mailbox could cause insertion of mail to that user's inbox, or any other of their mailboxes whose id was known to the user, despite having no insert permissions to the target mailbox.
An issue was discovered in Cyrus IMAP before 3.12.4. JMAP snooze bypas ...
An issue was discovered in Cyrus IMAP before 3.12.4. JMAP snooze bypasses the destination-mailbox ACL. An authenticated user with insert permissions on another user's snoozed mailbox could cause insertion of mail to that user's inbox, or any other of their mailboxes whose id was known to the user, despite having no insert permissions to the target mailbox.
4.3 Medium
CVSS3