CyberRota Analysis
AI-GeneratedDocker versions prior to 0.4.13 are vulnerable to an injection flaw that allows remote unauthenticated attackers to manipulate IMAP commands by exploiting improperly handled CRLF sequences. This could lead to unauthorized access and potential data breaches in authenticated mailbox connections, particularly if bearer-token authentication is not implemented. Organizations using affected Docker versions should prioritize immediate updates to mitigate this critical security risk.
Original NVD Description
Improper neutralization of CRLF sequences in IMAP command construction in psyb0t/docker-mailbox before 0.4.13 allows a remote unauthenticated attacker, when bearer-token authentication is not configured, to inject additional IMAP commands into an authenticated upstream mailbox connection via crafted folder, UID, or search values.