Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:29522
HistoryMar 01, 2021 - 12:09 a.m.

Directory Traversal

2021-03-0100:09:16
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13
isync
directory traversal
validation
imap
synchronization
mailbox names

EPSS

0.006

Percentile

78.2%

isync is vulnerable to directory traversal. The vulnerability exists as validations of the mailbox names returned by IMAP LIST/LSUB do not occur allowing a malicious or compromised server to use specially crafted mailbox names containing .. path components to access data outside the designated mailbox on the opposite end of the synchronization channel.