CVE-2022-39258
mailcow-dockerized critical information misrepresentation can lead to phishing attacks through Swagger UI
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
mailcow is a mailserver suite. A vulnerability innversions prior to 2022-09 allows an attacker to craft a custom Swagger API template to spoof Authorize links. This could redirect a victim to an attacker controller place to steal Swagger authorization credentials or create a phishing page to steal other information. The issue has been fixed with the 2022-09 mailcow Mootember Update. As a workaround, one may delete the Swapper API Documentation from their e-mail server.
mailcow es una suite de servidores de correo. Una vulnerabilidad en versiones anteriores a 09-2022 permite a un atacante diseñar una plantilla personalizada de la API Swagger para falsificar los enlaces de autorización. Esto podría redirigir a una víctima a un lugar de control del atacante para robar las credenciales de autorización de Swagger o crear una página de phishing para robar otra información. El problema ha sido corregido con la actualización de 09-2022 mailcow Mootember. Como mitigación, puede eliminarse la documentación de la API Swapper de su servidor de correo electrónico
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-09-02 CVE Reserved
- 2022-09-27 CVE Published
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
- CWE-451: User Interface (UI) Misrepresentation of Critical Information
- CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/mailcow/mailcow-dockerized/security/advisories/GHSA-vjgf-cp5p-wm45 | 2024-08-03 |
URL | Date | SRC |
---|---|---|
https://github.com/mailcow/mailcow-dockerized/pull/4766 | 2022-09-29 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mailcow Search vendor "Mailcow" | Mailcow: Dockerized Search vendor "Mailcow" for product "Mailcow: Dockerized" | < 2022-09 Search vendor "Mailcow" for product "Mailcow: Dockerized" and version " < 2022-09" | - |
Affected
|