PT-2024-26359 · Unknown · Stalwart Mail Server

Lukaslihotzki

·

Published

2024-05-15

·

Updated

2024-05-15

·

CVE-2024-35179

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Stalwart Mail Server versions prior to 0.8.0
Description The issue affects Stalwart Mail Server when using RUN AS USER, allowing the specified user and web interface admins to read arbitrary files as root. This issue impacts administrators who have set up Stalwart Mail Server with RUN AS USER and have handed out admin credentials, expecting these credentials to grant access according to the RUN AS USER settings. In scenarios where attackers achieve Arbitrary Code Execution using another vulnerability, this issue can be exploited.
Recommendations For versions prior to 0.8.0, update to version 0.8.0 to resolve the issue. As a temporary workaround, consider restricting access to sensitive files and directories to minimize the risk of exploitation. Avoid using the RUN AS USER feature until the issue is resolved by updating to version 0.8.0.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-35179
GHSA-5PFX-J27J-4C6H

Affected Products

Stalwart Mail Server