cyrus-imapd: privilege escalation in HTTP request
Published Nov 15, 2019
9.8
CRITICALCVSS 3.1
EPSS 2.39%
Description
Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection.
Affected products
No data.
Configuration 1
Configuration 2
- 30
- 31
Configuration 3
- 9.0
No data.
Red Hat Enterprise Linux 8
cyrus-imapd-0:3.0.7-19.el8
Fixed · RHSA-2020:4655
Red Hat Enterprise Linux 5
cyrus-imapd
Not affected
Red Hat Enterprise Linux 6
cyrus-imapd
Not affected
Red Hat Enterprise Linux 7
cyrus-imapd
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | cyrus-imapd-0:3.0.7-19.el8 | Fixed | RHSA-2020:4655 |
| Red Hat Enterprise Linux 5 | cyrus-imapd | Not affected | n/a |
| Red Hat Enterprise Linux 6 | cyrus-imapd | Not affected | n/a |
| Red Hat Enterprise Linux 7 | cyrus-imapd | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
If HTTP is enabled (e.g. RSS, CalDAV), cyrus-imapd does not properly authenticate a HTTP request coming through a connection that has been previously authenticated. Usually, this is not a problem, as each user will have their own connection and a breach of security boundaries would not be possible. An exception to this rule is if the cyrus-imapd HTTP service is behind a proxy, for example a reverse caching proxy, and said proxy reuses the same connection to cyrus-imapd for multiple requests.
References (10)
- https://access.redhat.com/security/cve/CVE-2019-18928 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1775177 Issue Tracking
- https://github.com/cyrusimap/cyrus-imapd/issues/2904
- https://lists.debian.org/debian-lts-announce/2022/06/msg00013.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LAGKPZDXQ6KRUGQVRAO6N4PCINP6KS5F/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PHV3TUU53WCKJ3BBRK2EHAF44MSZEFK6/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2019-18928
- https://www.cve.org/CVERecord?id=CVE-2019-18928
- https://www.cyrusimap.org/imap/download/release-notes/2.5/x/2.5.14.html x_refsource_MISCPatchRelease NotesThird Party Advisory
- https://www.cyrusimap.org/imap/download/release-notes/3.0/x/3.0.12.html x_refsource_MISCPatchRelease NotesThird Party Advisory
Change history (0)
No recorded changes yet.