CRITICAL
OpenDMARC through 1.3.2 and 1.4.x, when used with pypolicyd-spf 2.0.2, allows attacks that bypass SPF and DMARC authentication in situations where the HELO field is inconsistent with the MAIL FROM field
Published Apr 27, 2020
9.8
CRITICALCVSS 3.1
EPSS 2.62%
Description
OpenDMARC through 1.3.2 and 1.4.x, when used with pypolicyd-spf 2.0.2, allows attacks that bypass SPF and DMARC authentication in situations where the HELO field is inconsistent with the MAIL FROM field.
Affected products
No data.
Configuration 1
AND
- ≥ 1.3.0 · ≤ 1.3.2
- 1.4.0
- 2.0.2
Configuration 2
OR
- 33
- 34
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://bugs.launchpad.net/pypolicyd-spf/+bug/1838816 x_refsource_MISCExploitThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-11327 Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2D4JGHMALEJEWWG56DKR5OZB22TK7W5B/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KBOGOQOK3TIWWJV66MW5YWNRJAFFYGR5/ vendor-advisoryx_refsource_FEDORA
- https://sourceforge.net/p/opendmarc/tickets/235/ x_refsource_MISCExploitThird Party Advisory
- https://www.usenix.org/system/files/sec20fall_chen-jianjun_prepub_0.pdf x_refsource_MISCTechnical DescriptionThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://bugs.launchpad.net/pypolicyd-spf/+bug/1838816 | x_refsource_MISCExploitThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-11327 | Advisory | |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2D4JGHMALEJEWWG56DKR5OZB22TK7W5B/ | vendor-advisoryx_refsource_FEDORA | |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KBOGOQOK3TIWWJV66MW5YWNRJAFFYGR5/ | vendor-advisoryx_refsource_FEDORA | |
| https://sourceforge.net/p/opendmarc/tickets/235/ | x_refsource_MISCExploitThird Party Advisory | |
| https://www.usenix.org/system/files/sec20fall_chen-jianjun_prepub_0.pdf | x_refsource_MISCTechnical DescriptionThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 27, 2020
Updated Aug 5, 2024
Reserved Apr 27, 2020
Link CVE-2019-20790
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data