Skip to content

Path Traversal and Arbitrary Code Execution Vulnerability

Moderate
FreddleSpl0it published GHSA-4m8r-87gc-3vvp Apr 4, 2024

Package

mailcow: dockerized

Affected versions

< 2024-04.

Patched versions

>= 2024-04.

Description

Impact

A security vulnerability has been identified in mailcow affecting versions < 2024-04. This vulnerability is a combination of path traversal and arbitrary code execution, specifically targeting the rspamd_maps() function. It allows authenticated admin users to overwrite any file writable by the www-data user by exploiting improper path validation. The exploit chain can lead to the execution of arbitrary commands on the server.

Patches

Versions including 2024-04 and later

Severity

Moderate
6.7
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
High
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
Low
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L

CVE ID

CVE-2024-30270

Weaknesses

No CWEs

Credits