CVE-2019-19783

An issue was discovered in Cyrus IMAP before 2.5.15, 3.0.x before 3.0.13, and 3.1.x through 3.1.8. If sieve script uploading is allowed (3.x) or certain non-default sieve options are enabled (2.x), a user with a mail account on the service can use a sieve script containing a fileinto directive to create any mailbox with administrator privileges, because of folder mishandling in autosieve_createfolder() in imap/lmtp_sieve.c.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 62%
VendorProductVersion
cyrusimap
2.5.0 ≤
𝑥
< 2.5.15
cyrusimap
3.0.0 ≤
𝑥
< 3.0.13
cyrusimap
3.1.0 ≤
𝑥
< 3.1.8
debiandebian_linux
9.0
debiandebian_linux
10.0
canonicalubuntu_linux
18.04
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
cyrus-imapd
bullseye
3.2.6-2+deb11u2
fixed
bookworm
3.6.1-4+deb12u3
fixed
bookworm (security)
3.6.1-4+deb12u2
fixed
sid
3.10.0-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
cyrus-imapd
focal
not-affected
eoan
ignored
disco
ignored
bionic
Fixed 2.5.10-3ubuntu1.1
released
xenial
dne
trusty
dne