3.5
CVSSv2

CVE-2019-19783

Published: 16/12/2019 Updated: 07/11/2023
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

An issue exists in Cyrus IMAP prior to 2.5.15, 3.0.x prior to 3.0.13, and 3.1.x up to and including 3.1.8. If sieve script uploading is allowed (3.x) or certain non-default sieve options are enabled (2.x), a user with a mail account on the service can use a sieve script containing a fileinto directive to create any mailbox with administrator privileges, because of folder mishandling in autosieve_createfolder() in imap/lmtp_sieve.c.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cyrus imap

debian debian linux 9.0

debian debian linux 10.0

fedoraproject fedora 30

fedoraproject fedora 31

canonical ubuntu linux 18.04

Vendor Advisories

Synopsis Moderate: cyrus-imapd security update Type/Severity Security Advisory: Moderate Topic An update for cyrus-imapd is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base s ...
It was discovered that the lmtpd component of the Cyrus IMAP server created mailboxes with administrator privileges if the fileinto was used, bypassing ACL checks For the oldstable distribution (stretch), this problem has been fixed in version 2510-3+deb9u2 For the stable distribution (buster), this problem has been fixed in version 308-6+deb ...