CyberRota Analysis
AI-GeneratedCyrus IMAP versions up to 3.12.2 are vulnerable due to a flaw in the GENURLAUTH command that allows authenticated users to generate URLAUTH tokens for any mailbox, bypassing access control lists (ACLs). This vulnerability enables unauthorized access to mailbox contents, potentially exposing sensitive information. Organizations using affected versions of Cyrus IMAP should prioritize remediation to prevent unauthorized data access.
Original NVD Description
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. GENURLAUTH-issued tokens can bypass ACLs. Any authenticated user could mint a URLAUTH token (via the GENURLAUTH command) for any mailbox they could name, even without read access on it. This would allow reading mail from mailboxes despite having no granted permissions.