CVE-2022-22931: Relative Path Traversal
(updated )
Fix of CVE-2021-40525 do not prepend delimiters upon valid directory validations. Affected implementations include: - maildir mailbox store - Sieve file repository This enables a user to access other users data stores (limited to user names being prefixed by the value of the username being used).
References
- github.com/advisories/GHSA-v84g-cf5j-xjqx
- github.com/apache/james-project/pull/877
- github.com/apache/james-project/pull/877/commits/b1e891a9e5eeadfa1d779ae50f21c73efe4d2fc7
- lists.apache.org/thread/bp8yql4wws56jlh0vxoowj7foothsmpr
- nvd.nist.gov/vuln/detail/CVE-2022-22931
- www.openwall.com/lists/oss-security/2022/02/07/1
Detect and mitigate CVE-2022-22931 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →