CVE-2021-20247

HIGH

mbsync < 1.3.5 - Path Traversal via IMAP Mailbox Name

Title source: llm
STIX 2.1

Description

A flaw was found in mbsync before v1.3.5 and v1.4.1. Validations of the mailbox names returned by IMAP LIST/LSUB do not occur allowing a malicious or compromised server to use specially crafted mailbox names containing '..' path components to access data outside the designated mailbox on the opposite end of the synchronization channel. The highest threat from this vulnerability is to data confidentiality and integrity.

References (6)

Core 6
Core References
Issue Tracking, Third Party Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=1928963
Exploit, Mailing List, Third Party Advisory x_refsource_misc
https://www.openwall.com/lists/oss-security/2021/02/22/1
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2022/07/msg00001.html
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/202208-15

Scores

CVSS v3 7.4
EPSS 0.0188
EPSS Percentile 76.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-20 CWE-22
Status published
Products (5)
debian/debian_linux 9.0
fedoraproject/extra_packages_for_enterprise_linux 8.0
fedoraproject/fedora 32
fedoraproject/fedora 33
mbsync_project/mbsync < 1.3.5
Published Feb 23, 2021
Tracked Since Feb 18, 2026