PT-2022-20557 · Unknown · Mailcow-Dockerized

Derlinkman

+1

·

Published

2022-07-11

·

Updated

2022-07-18

·

CVE-2022-31138

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions mailcow-dockerized versions prior to 2022-06a
Description The issue concerns an extended privilege vulnerability in mailcow, a mailserver suite. This vulnerability can be exploited by manipulating custom parameters such as regexmess, skipmess, regexflag, delete2foldersonly, delete2foldersbutnot, regextrans2, pipemess, or maxlinelengthcmd to execute arbitrary code.
Recommendations For versions prior to 2022-06a, update the mailcow instance with the update.sh script in the mailcow root directory to 2022-06a or newer to receive a patch for this issue. As a temporary workaround, consider removing the Syncjob ACL from all mailbox users to prevent changes to those settings.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-31138
GHSA-VX9W-H33P-5VHC

Affected Products

Mailcow-Dockerized