PT-2020-18335 · Mailu · Mailu

Highkaiyou

·

Published

2020-02-13

·

Updated

2020-02-18

·

CVE-2020-5239

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mailu versions prior to 1.7
Description An authenticated user can exploit a vulnerability in the Mailu fetchmail script and gain full access to a Mailu instance. Mailu servers with open registration or untrusted users are most impacted.
Recommendations For versions prior to 1.7, update to version 1.7 or later, where the master and 1.7 branches are patched on the git repository. Additionally, use the patched Docker images published on docker.io/mailu for tags 1.5, 1.6, 1.7, and master. Follow the detailed instructions about patching and securing the server afterwards.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-5239
GHSA-2467-P5GV-58Q6

Affected Products

Mailu