Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2023-34108— Manipulation of Internal Dovecot Variables in mailcow via crafted Passwords

Quick assessment

Affected
mailcow mailcow-dockerized
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

mailcow是一个邮件服务器套件。 mailcow 存在操作系统命令注入漏洞,该漏洞源于允许攻击者在身份验证过程中使用特制密码来操纵内部Dovecot变量。

CVSS 8.8 · High EPSS 0.98% · P61
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2023-34108

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Manipulation of Internal Dovecot Variables in mailcow via crafted Passwords
Source: CVE Program / CVE List V5
Vulnerability Description
mailcow is a mail server suite based on Dovecot, Postfix and other open source software, that provides a modern web UI for user/server administration. A vulnerability has been discovered in mailcow which allows an attacker to manipulate internal Dovecot variables by using specially crafted passwords during the authentication process. The issue arises from the behavior of the `passwd-verify.lua` script, which is responsible for verifying user passwords during login attempts. Upon a successful login, the script returns a response in the format of "password=<valid-password>", indicating the successful authentication. By crafting a password with additional key-value pairs appended to it, an attacker can manipulate the returned string and influence the internal behavior of Dovecot. For example, using the password "123 mail_crypt_save_version=0" would cause the `passwd-verify.lua` script to return the string "password=123 mail_crypt_save_version=0". Consequently, Dovecot will interpret this string and set the internal variables accordingly, leading to unintended consequences. This vulnerability can be exploited by an authenticated attacker who has the ability to set their own password. Successful exploitation of this vulnerability could result in unauthorized access to user accounts, bypassing security controls, or other malicious activities. This issue has been patched in version `2023-05a`. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Source: CVE Program / CVE List V5
Vulnerability Title
mailcow 操作系统命令注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
mailcow是一个邮件服务器套件。 mailcow 存在操作系统命令注入漏洞,该漏洞源于允许攻击者在身份验证过程中使用特制密码来操纵内部Dovecot变量。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
mailcow mailcow-dockerized < 2023-05a -

II. Public POCs for CVE-2023-34108

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-34108

请登录查看更多情报信息。

Patches & Fixes for CVE-2023-34108 (1)

Vendor Advisories for CVE-2023-34108 (1)

Other References for CVE-2023-34108 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2023-34108

No comments yet


Leave a comment