Skip to content

CVE-2022-31245: IMAPSYNC (Syncjobs) Debug Extended Rights (pipemess)

Critical
DerLinkman published GHSA-jr64-xv4c-4g6c May 21, 2022

Package

IMAPSYNC (mailcow-dockerized)

Affected versions

< 2022-05d

Patched versions

>= 2022-05d

Description

Impact

An extended privilege vulnerability can be exploited by manipulating the debug argument pipmess or pipemes with command line inputs. CWE defines the issue as CWE-78, and the impact on confidentiality, integrity, and availability is expected.

Workaround

As a temporary workaround the Syncjob ACL can be removed from all mailbox users, preventing from changing those settings.

Solution

Update your mailcow instance with the update.sh script in the mailcow root directory to 2022-05d or newer.
You can check your version after the update in two ways:

  1. Login into your Admin UI and take a look at the bottom right.
  2. Do git describe --tags `git rev-list --tags --max-count=1 in your mailcow root directory after you´ve updated.

References

For more information

If you have any questions or comments about this advisory:

Severity

Critical

CVE ID

CVE-2022-31245

Weaknesses

Credits