mailcow before 2022-05d allows a remote authenticated user to inject OS commands and escalate privileges to domain admin via the --debug option in conjunction with the ---PIPEMESS option in Sync Jobs.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T07:11:39.879Z
Reserved: 2022-05-20T00:00:00
Link: CVE-2022-31245
No data.
Status : Modified
Published: 2022-05-20T15:15:10.280
Modified: 2024-11-21T07:04:12.570
Link: CVE-2022-31245
No data.
OpenCVE Enrichment
No data.
Weaknesses