Hoşgeldin Misafir

MailDepot 2032 SP2 Session Expiration Vulnerability

Asım Gürsoy

mersin
27 Mar 2020
8,833 Mesaj

Aktiflik

Seviye

Deneyim

TIM / GÖREV:
MailDepot 2032 SP2 Session Expiration Vulnerability--


Kod:
Product:                   MailDepot
Manufacturer:              REDDOXX GmbH
Affected Version(s):       2032 SP2 (2.2.1242)
Tested Version(s):         2032 SP2 (2.2.1242)
Vulnerability Type:        Insufficient Session Expiration (CWE-613)
Risk Level:                Low
Solution Status:           Fixed
Manufacturer Notification: 2019-11-19
Solution Date:             2020-06-09
Public Disclosure:         2020-09-29
CVE Reference:             CVE-2019-19199
Authors of Advisory:       Micha Borrmann (SySS GmbH)
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
Overview:
 
REDDOXX MailDepot is an e-mail archiving solution with many features
and an optional web browser user interface.
 
The manufacturer describes the product as follows (see [1]):
 
"The email archiving solution works independently from the type of mail
server, supports any type of storage and can therefore be easily
integrated into any existing infrastructure."
 
Due to the improper server-side invalidation of authentication tokens
when using the logout function, authentication tokens can still be
used.
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
Vulnerability Details:
 
After using the logout function, the assigned authentication token for
the REST web service can still be used for many hours, because it
is only invalidated on the client, but not on the server side.
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
Proof of Concept (PoC):
 
Storing and reusing the assigned authentication ID can easily be
demonstrated with a modifying web proxy.
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
Solution:
 
Install the provided security update.
 
#  0day.today [2020-10-01]  #