CVE-2022-31138
Last modified
CVE-2022-31138 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. mailcow is a mailserver suite. Prior to mailcow-dockerized version 2022-06a, an extended privilege vulnerability can be exploited by manipulating the custom parameters regexmess, skipmess, regexflag, delete2foldersonly, delete2foldersbutnot, regextrans2, pipemess, or maxlinelengthcmd to execute arbitrary code. EPSS estimates a 2.34% chance of exploitation in the next 30 days.
Description
mailcow is a mailserver suite. Prior to mailcow-dockerized version 2022-06a, an extended privilege vulnerability can be exploited by manipulating the custom parameters regexmess, skipmess, regexflag, delete2foldersonly, delete2foldersbutnot, regextrans2, pipemess, or maxlinelengthcmd to execute arbitrary code. Users should update their mailcow instances with the `update.sh` script in the mailcow root directory to 2022-06a or newer to receive a patch for this issue. As a temporary workaround, the Syncjob ACL can be removed from all mailbox users, preventing changes to those settings.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mailcow | Mailcow\ | < 2022-06a |
References
- https://github.com/ly1g3/Mailcow-CVE-2022-31138Exploit, Third Party Advisory
- https://github.com/mailcow/mailcow-dockerized/commit/d373164e13a14e058f82c9f1918a5612f375a9f9Patch, Third Party Advisory
- https://github.com/mailcow/mailcow-dockerized/releases/tag/2022-06aRelease Notes, Third Party Advisory
- https://github.com/mailcow/mailcow-dockerized/security/advisories/GHSA-vx9w-h33p-5vhcMitigation, Third Party Advisory
- https://github.com/ly1g3/Mailcow-CVE-2022-31138Exploit, Third Party Advisory
- https://github.com/mailcow/mailcow-dockerized/commit/d373164e13a14e058f82c9f1918a5612f375a9f9Patch, Third Party Advisory
- https://github.com/mailcow/mailcow-dockerized/releases/tag/2022-06aRelease Notes, Third Party Advisory
- https://github.com/mailcow/mailcow-dockerized/security/advisories/GHSA-vx9w-h33p-5vhcMitigation, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-31138?
How severe is CVE-2022-31138?
How do I fix CVE-2022-31138?
Are you affected by CVE-2022-31138?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
