CVE-2022-31245

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
20/05/2022
Last modified:
02/06/2022

Description

mailcow before 2022-05d allows a remote authenticated user to inject OS commands and escalate privileges to domain admin via the --debug option in conjunction with the ---PIPEMESS option in Sync Jobs.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mailcow:mailcow\:_dockerized:*:*:*:*:*:*:*:* 2022-05d (excluding)