Impact
A flaw in the Cyrus IMAP authentication system allows URLAUTH URLs that were minted while an authorizer had access to remain valid even after that access has been revoked. This means an attacker who obtains such a URL can continue to use it to authenticate and access mailbox data, potentially gaining unauthorized email access or session hijacking. The weakness stems from improper authorization handling (CWE-613 and CWE-672).
Affected Systems
The vulnerability affects the Cyrus IMAP server, specifically all versions through and including 3.12.2. Users running 3.12.2 or earlier are susceptible until an update is applied.
Risk and Exploitability
The CVSS score of 3.5 indicates low severity, and the EPSS score of less than 1% reflects a very low exploitation probability. The flaw is not listed in the CISA KEV catalog, suggesting no known widespread exploitation. The likely attack vector is remote, requiring an attacker to possess or intercept a URLAUTH URL that was minted while an account had permission and then use it after that permission has been revoked. The conditions for exploitation are therefore relatively specific, reducing the overall risk, but the potential for unauthorized access to sensitive mail remains significant for affected systems.
OpenCVE Enrichment