QID 375962

Date Published: 2021-11-03

QID 375962: Cyrus IMAP Server Access Control Vulnerability

Cyrus IMAP is an email, contacts and calendar server. Cyrus is free and open source.

Affected Version:
Cyrus IMAP version 3.4.0 and earlier
Cyrus IMAP version 3.2.6 and earlier

QID Detection Logic (Authenticated Unix):
This QID checks for vulnerable versions of Cyrus IMAP by executing "cyr_info version" command.

The vulnerability allows remote authenticated users to bypass intended access restrictions on server annotations and consequently cause replication to stall.

  • CVSS V3 rated as Medium - 4.3 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution
    The Vendor has released security update to fix the vulnerability. For more information please visit the following links based on the version Cyrus IMAP version 3.4.1 and Cyrus IMAP version 3.2.7

    CVEs related to QID 375962

    Software Advisories
    Advisory ID Software Component Link
    CVE-2021-32056 URL Logo www.cyrusimap.org/imap/download/release-notes/3.4/x/3.4.1.html
    CVE-2021-32056 URL Logo www.cyrusimap.org/imap/download/release-notes/3.2/x/3.2.7.html