Impact
The vulnerability allows an attacker to spoof the identity of a trusted proxy by sending a crafted X-Forwarded-By header, thereby bypassing the authentication controls that rely on header‑based proxy authentication. This results in unauthorized access to the mail server, enabling retrieval or manipulation of mail data.
Affected Systems
Mailu mail server deployed via Docker images, versions 2.0 through 2024.06.55, and Mailu helm‑charts prior to 2.7.3, when the configuration includes PROXY_AUTH_WHITELIST while REAL_IP_HEADER is not set. These settings cause the application to accept the X‑Forwarded‑By header as a trusted proxy identifier.
Risk and Exploitability
The CVSS score of 9.8 reflects a critical severity. EPSS is not available, and the vulnerability is not listed in KEV, but a remote attacker can exploit it over the network by injecting a header into an HTTP request. Based on the description, the likely attack vector is remote HTTP header injection, potentially allowing unrestricted access to the mail service without authentication. Immediate remediation is required.
OpenCVE Enrichment