{"api_version":"1","generated_at":"2026-07-23T21:15:37+00:00","cve":"CVE-2021-20247","urls":{"html":"https://cve.report/CVE-2021-20247","api":"https://cve.report/api/cve/CVE-2021-20247.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-20247","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-20247"},"summary":{"title":"CVE-2021-20247","description":"A flaw was found in mbsync before v1.3.5 and v1.4.1. Validations of the mailbox names returned by IMAP LIST/LSUB do not occur allowing a malicious or compromised server to use specially crafted mailbox names containing '..' path components to access data outside the designated mailbox on the opposite end of the synchronization channel. The highest threat from this vulnerability is to data confidentiality and integrity.","state":"PUBLIC","assigner":"secalert@redhat.com","published_at":"2021-02-23 19:15:00","updated_at":"2023-11-07 03:29:00"},"problem_types":["CWE-22"],"metrics":[],"references":[{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1928963","name":"https://bugzilla.redhat.com/show_bug.cgi?id=1928963","refsource":"MISC","tags":["Issue Tracking","Third Party Advisory"],"title":"1928963 – (CVE-2021-20247) CVE-2021-20247 isync/mbsync: mailbox names returned by IMAP LIST/LSUB not validated","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CAXQLCK35QGRCRENRTGKJO4VVZGUXUJJ/","name":"FEDORA-2021-954ebabcf7","refsource":"","tags":[],"title":"[SECURITY] Fedora 32 Update: isync-1.4.1-1.fc32 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://security.gentoo.org/glsa/202208-15","name":"GLSA-202208-15","refsource":"GENTOO","tags":[],"title":"isync: Multiple Vulnerabilities (GLSA 202208-15) — Gentoo security","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.openwall.com/lists/oss-security/2021/02/22/1","name":"https://www.openwall.com/lists/oss-security/2021/02/22/1","refsource":"MISC","tags":["Exploit","Mailing List","Third Party Advisory"],"title":"oss-security - CVE-2021-20247: isync/mbsync data leak/destruction vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CAXQLCK35QGRCRENRTGKJO4VVZGUXUJJ/","name":"FEDORA-2021-954ebabcf7","refsource":"FEDORA","tags":["Mailing List","Third Party Advisory"],"title":"[SECURITY] Fedora 32 Update: isync-1.4.1-1.fc32 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GVDEBZQJMWDW5JFK4NTHH6DAFNAZTESW/","name":"FEDORA-2021-ef8c2acfce","refsource":"FEDORA","tags":["Mailing List","Third Party Advisory"],"title":"[SECURITY] Fedora 33 Update: isync-1.4.1-1.fc33 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://lists.debian.org/debian-lts-announce/2022/07/msg00001.html","name":"[debian-lts-announce] 20220701 [SECURITY] [DLA 3066-1] isync security update","refsource":"MLIST","tags":[],"title":"[SECURITY] [DLA 3066-1] isync security update","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GVDEBZQJMWDW5JFK4NTHH6DAFNAZTESW/","name":"FEDORA-2021-ef8c2acfce","refsource":"","tags":[],"title":"[SECURITY] Fedora 33 Update: isync-1.4.1-1.fc33 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-20247","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-20247","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"20247","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"9.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"20247","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"fedoraproject","cpe5":"extra_packages_for_enterprise_linux","cpe6":"8.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"20247","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"fedoraproject","cpe5":"extra_packages_for_enterprise_linux","cpe6":"8.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"20247","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"32","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"20247","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"33","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"20247","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"32","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"20247","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"33","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"20247","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mbsync_project","cpe5":"mbsync","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"20247","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mbsync_project","cpe5":"mbsync","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2021-20247","qid":"179393","title":"Debian Security Update for isync (CVE-2021-20247)"},{"cve":"CVE-2021-20247","qid":"180384","title":"Debian Security Update for isync (DLA 3066-1)"},{"cve":"CVE-2021-20247","qid":"281601","title":"Fedora Security Update for isync (FEDORA-2021-954ebabcf7)"},{"cve":"CVE-2021-20247","qid":"281602","title":"Fedora Security Update for isync (FEDORA-2021-ef8c2acfce)"},{"cve":"CVE-2021-20247","qid":"501585","title":"Alpine Linux Security Update for isync"},{"cve":"CVE-2021-20247","qid":"501869","title":"Alpine Linux Security Update for isync"},{"cve":"CVE-2021-20247","qid":"710592","title":"Gentoo Linux isync Multiple Vulnerabilities (GLSA 202208-15)"},{"cve":"CVE-2021-20247","qid":"750281","title":"OpenSUSE Security Update for isync (openSUSE-SU-2021:0516-1)"}]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2021-20247","ASSIGNER":"secalert@redhat.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"n/a","product":{"product_data":[{"product_name":"isync/mbsync","version":{"version_data":[{"version_value":"before 1.35"},{"version_value":"before 1.4.1"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-20->CWE-22"}]}]},"references":{"reference_data":[{"refsource":"MISC","name":"https://bugzilla.redhat.com/show_bug.cgi?id=1928963","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1928963"},{"refsource":"MISC","name":"https://www.openwall.com/lists/oss-security/2021/02/22/1","url":"https://www.openwall.com/lists/oss-security/2021/02/22/1"},{"refsource":"FEDORA","name":"FEDORA-2021-954ebabcf7","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CAXQLCK35QGRCRENRTGKJO4VVZGUXUJJ/"},{"refsource":"FEDORA","name":"FEDORA-2021-ef8c2acfce","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GVDEBZQJMWDW5JFK4NTHH6DAFNAZTESW/"},{"refsource":"MLIST","name":"[debian-lts-announce] 20220701 [SECURITY] [DLA 3066-1] isync security update","url":"https://lists.debian.org/debian-lts-announce/2022/07/msg00001.html"},{"refsource":"GENTOO","name":"GLSA-202208-15","url":"https://security.gentoo.org/glsa/202208-15"}]},"description":{"description_data":[{"lang":"eng","value":"A flaw was found in mbsync before v1.3.5 and v1.4.1. Validations of the mailbox names returned by IMAP LIST/LSUB do not occur allowing a malicious or compromised server to use specially crafted mailbox names containing '..' path components to access data outside the designated mailbox on the opposite end of the synchronization channel. The highest threat from this vulnerability is to data confidentiality and integrity."}]}},"nvd":{"publishedDate":"2021-02-23 19:15:00","lastModifiedDate":"2023-11-07 03:29:00","problem_types":["CWE-22"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.4,"baseSeverity":"HIGH"},"exploitabilityScore":2.2,"impactScore":5.2},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":5.8},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:mbsync_project:mbsync:*:*:*:*:*:*:*:*","versionStartIncluding":"1.4.0","versionEndExcluding":"1.4.1","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:mbsync_project:mbsync:*:*:*:*:*:*:*:*","versionEndExcluding":"1.3.5","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:fedoraproject:extra_packages_for_enterprise_linux:8.0:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"20247","Ordinal":"194288","Title":"CVE-2021-20247","CVE":"CVE-2021-20247","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"20247","Ordinal":"1","NoteData":"A flaw was found in mbsync before v1.3.5 and v1.4.1. Validations of the mailbox names returned by IMAP LIST/LSUB do not occur allowing a malicious or compromised server to use specially crafted mailbox names containing '..' path components to access data outside the designated mailbox on the opposite end of the synchronization channel. The highest threat from this vulnerability is to data confidentiality and integrity.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"20247","Ordinal":"2","NoteData":"2021-02-23","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"20247","Ordinal":"3","NoteData":"2021-03-04","Type":"Other","Title":"Modified"}]}}}