PT-2020-18335 · Mailu · Mailu
Highkaiyou
·
Published
2020-02-13
·
Updated
2020-02-18
·
CVE-2020-5239
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Mailu versions prior to 1.7
Description
An authenticated user can exploit a vulnerability in the Mailu fetchmail script and gain full access to a Mailu instance. Mailu servers with open registration or untrusted users are most impacted.
Recommendations
For versions prior to 1.7, update to version 1.7 or later, where the master and 1.7 branches are patched on the git repository. Additionally, use the patched Docker images published on docker.io/mailu for tags 1.5, 1.6, 1.7, and master. Follow the detailed instructions about patching and securing the server afterwards.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mailu