Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH token forgery can occur via a missing mboxkey. If an attacker knew a folder name on the victim's account for which the victim had never issued an auth URL, they could forge a working URLAUTH token by computing an HMAC-SHA1 value with a predictable key, giving them read access to the mailbox. (URLAUTH is an obscure feature, meaning that the odds of any user actually being susceptible to this attack are very low. Perhaps no public clients use URLAUTH.)
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N
Vulnerability Type
可预测问题
Vulnerability Title
cyrusimap Cyrus IMAP 加密问题漏洞
Vulnerability Description
cyrusimap Cyrus IMAP是cyrusimap团队开源的一款支持IMAP协议的邮件服务器。 cyrusimap Cyrus IMAP 3.12.2及之前版本存在加密问题漏洞,该漏洞源于缺失mboxkey导致URLAUTH令牌伪造,攻击者可能通过预测HMAC-SHA1值伪造令牌,读取收件箱。
CVSS Information
N/A
Vulnerability Type
N/A