MailDepot 2032 SP2 Session Expiration

Risk: Low
Local: No
Remote: No
CWE: CWE-613

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Advisory ID: SYSS-2019-049 Product: MailDepot Manufacturer: REDDOXX GmbH Affected Version(s): 2032 SP2 (2.2.1242) Tested Version(s): 2032 SP2 (2.2.1242) Vulnerability Type: Insufficient Session Expiration (CWE-613) Risk Level: Low Solution Status: Fixed Manufacturer Notification: 2019-11-19 Solution Date: 2020-06-09 Public Disclosure: 2020-09-29 CVE Reference: CVE-2019-19199 Authors of Advisory: Micha Borrmann (SySS GmbH) ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Overview: REDDOXX MailDepot is an e-mail archiving solution with many features and an optional web browser user interface. The manufacturer describes the product as follows (see [1]): "The email archiving solution works independently from the type of mail server, supports any type of storage and can therefore be easily integrated into any existing infrastructure." Due to the improper server-side invalidation of authentication tokens when using the logout function, authentication tokens can still be used. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Vulnerability Details: After using the logout function, the assigned authentication token for the REST web service can still be used for many hours, because it is only invalidated on the client, but not on the server side. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Proof of Concept (PoC): Storing and reusing the assigned authentication ID can easily be demonstrated with a modifying web proxy. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Solution: Install the provided security update. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Disclosure Timeline: 2019-11-18: Detection of the vulnerability 2019-11-19: Vulnerability reported to manufacturer 2019-11-20: Manufacturer confirms vulnerability 2019-11-21: CVE number assigned 2020-06-09: Update was released from the vendor [2] 2020-09-29: Public release of the security advisory ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ References: [1] REDDOXX MailDepot Product Website [2] REDDOXX Release Information [3] SySS Security Advisory SYSS-2019-049 [4] SySS Responsible Disclosure Policy ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Credits: This security vulnerability was found by Micha Borrmann of SySS GmbH. E-Mail: micha.borrmann (at) Public Key: Key Fingerprint: 38BD 7A9C 3EA9 39C5 33F9 94D0 CFC2 D5B0 8EE0 CBB9 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Disclaimer: The information provided in this security advisory is provided "as is" and without warranty of any kind. Details of this security advisory may be updated in order to provide as accurate information as possible. The latest version of this security advisory is available on the SySS website. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Copyright: Creative Commons - Attribution (by) - Version 3.0 URL: -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEOL16nD6pOcUz+ZTQz8LVsI7gy7kFAl9y7R8ACgkQz8LVsI7g y7msaw/+IQdUT+LQWLfFcMAacz6WeLAhwqeaZytwhu8map8msHIncMpxWPddU78K 8lcgR5zIF2bKmj6PXC8vYnwpYiiY83wCrIRoVN/SGB2dXTulv1CK6uuIAH/mHcZ9 hYG1vBxJFkC0hm0Un89GTFC0v+dnlgFW7xAPd7q1uaAY07hLYUhGHijF5snCO9V6 FdXF1FlZJJNyoClk3qztolldwyQ5+pOZgupCe33/CN5qzCc7wH2VNTJEcGDT96Du fSFcVCcl1w/Mrs+8JeShr6aH/G1v3UVAe8+2xgDhzic5kxzpKjeWA1IdYvG7Q2nn Bf3d8zO+WYxCGrkdx5XJaJ4xKrM/r2Cz/5ipazYIdBLrrzYnXgdvQFJckKF+LZCy F1WTutrmbTG8kOpOq6qBf28lpJd8VKtilqTDuPs1VnOYU08Y1rYCMcsGjJVCQ7W5 mqH6bDuXBF9jzeeUq+H8G458bmINnKut9jEHgSMMA69iaIqjs9wzhmMg9imN4SyB zA8v/3lpz2bmTm/hZbo41gwGMETurwKsMK9StkY78TzbrbICYyTU6hsFFLalL76u GC13rF2Xs6T/I1CIeUfjjw3TpdKswhAy3o5d4VGck0Ye4eSROg2H8ksj+uR6O4TJ Lw+CvXJoM+g9ykqZbwkkV4vcPHUa/Ti7cbrmhNQUNZE13w/G8Zc= =RcMS -----END PGP SIGNATURE-----

Vote for this issue:


Thanks for you vote!


Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.

(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2020,


Back to Top