CyberRota Analysis
AI-GeneratedThe vacation "fcc" feature in Cyrus IMAP versions up to 3.12.2 allows users to bypass destination-mailbox access control lists (ACLs), enabling them to deliver auto-reply copies to any specified mailbox, even if they lack insert permissions. This vulnerability could lead to unauthorized access to mailbox contents, potentially exposing sensitive information. Organizations using affected versions of Cyrus IMAP should prioritize remediation to mitigate the risk of data leakage.
Original NVD Description
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The vacation "fcc" feature skips the destination-mailbox ACL. A user whose vacation Sieve script used :fcc (to save a copy of the sent message) could deliver vacation auto-reply copies into any mailbox the script could name, regardless of whether the script owner had insert permissions on the destination mailbox.