CVE-2020-29547

An issue was discovered in Citadel through webcit-926. Meddler-in-the-middle attackers can pipeline commands after POP3 STLS, IMAP STARTTLS, or SMTP STARTTLS commands, injecting cleartext commands into an encrypted user session. This can lead to credential disclosure.
Configurations

Configuration 1 (hide)

cpe:2.3:a:citadel:webcit:*:*:*:*:*:*:*:*

History

05 Jun 2023, 16:37

Type Values Removed Values Added
References (MISC) http://uncensored.citadel.org/dotgoto?room=Citadel%20Security - (MISC) http://uncensored.citadel.org/dotgoto?room=Citadel%20Security - Issue Tracking
References (MISC) http://uncensored.citadel.org/msg/4576039 - (MISC) http://uncensored.citadel.org/msg/4576039 - Vendor Advisory
CWE CWE-77
First Time Citadel webcit
Citadel
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.9
CPE cpe:2.3:a:citadel:webcit:*:*:*:*:*:*:*:*

29 May 2023, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-05-29 19:15

Updated : 2024-02-28 20:13


NVD link : CVE-2020-29547

Mitre link : CVE-2020-29547

CVE.ORG link : CVE-2020-29547


JSON object : View

Products Affected

citadel

  • webcit
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')