Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Attacker can use the IMAP SETACL command to inject the anyone permission to user's dovecot-acl file even if imap_acl_allow_anyone=no. This causes folders to be spammed to all users. The impact is limited to being able to spam folders to other users, no unexpected access is gained. Install to fixed version. No publicly available exploits are known.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
Vulnerability Type
访问控制不恰当
Vulnerability Title
Open-Xchange OX Dovecot Pro 访问控制错误漏洞
Vulnerability Description
Open-Xchange OX Dovecot Pro是德国Open-Xchange公司的一个邮件存储与投递系统。 Open-Xchange OX Dovecot Pro存在访问控制错误漏洞,该漏洞源于IMAP SETACL命令可注入anyone权限到用户dovecot-acl文件,即使imap_acl_allow_anyone=no设置,导致文件夹被垃圾邮件发送给所有用户。
CVSS Information
N/A
Vulnerability Type
N/A