Lucene search

K
prionPRIOn knowledge basePRION:CVE-2021-37845
HistoryMay 29, 2023 - 7:15 p.m.

Command injection

2023-05-2919:15:00
PRIOn knowledge base
www.prio-n.com
1
citadel
webcit-932
session fixation
cleartext phase
starttls command
rfc2595
meddler-in-the-middle
imap mailbox
email messages

4.2 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

32.3%

An issue was discovered in Citadel through webcit-932. A meddler-in-the-middle attacker can fixate their own session during the cleartext phase before a STARTTLS command (a violation of “The STARTTLS command is only valid in non-authenticated state.” in RFC2595). This potentially allows an attacker to cause a victim’s e-mail messages to be stored into an attacker’s IMAP mailbox, but depends on details of the victim’s client behavior.

CPENameOperatorVersion
webcitle932

4.2 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

32.3%

Related for PRION:CVE-2021-37845