CVE-2019-19783

Severity CVSS v4.0:
Pending analysis
Type:
CWE-269 Improper Privilege Management
Publication date:
16/12/2019
Last modified:
07/11/2023

Description

An issue was discovered in Cyrus IMAP before 2.5.15, 3.0.x before 3.0.13, and 3.1.x through 3.1.8. If sieve script uploading is allowed (3.x) or certain non-default sieve options are enabled (2.x), a user with a mail account on the service can use a sieve script containing a fileinto directive to create any mailbox with administrator privileges, because of folder mishandling in autosieve_createfolder() in imap/lmtp_sieve.c.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cyrus:imap:*:*:*:*:*:*:*:* 2.5.0 (including) 2.5.15 (excluding)
cpe:2.3:a:cyrus:imap:*:*:*:*:*:*:*:* 3.0.0 (including) 3.0.13 (excluding)
cpe:2.3:a:cyrus:imap:*:*:*:*:*:*:*:* 3.1.0 (including) 3.1.8 (excluding)
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*