The Roundcube component of Analogic Poste.io 2.1.6 uses .htaccess to protect the logs/ folder, which is effective with the Apache HTTP Server but is ineffective with nginx. Attackers can read logs via the webmail/logs/sendmail URI.
References
Link | Resource |
---|---|
https://poste.io/changelog | Release Notes Vendor Advisory |
https://bitbucket.org/analogic/mailserver/issues/665/posteio-logs-leak | Exploit Issue Tracking Third Party Advisory |
Configurations
Information
Published : 2019-06-24 07:15
Updated : 2019-06-27 10:35
NVD link : CVE-2019-12938
Mitre link : CVE-2019-12938
JSON object : View
CWE
CWE-693
Protection Mechanism Failure
Products Affected
analogic
- poste.io