CVE Database
/

CVE-2017-5658

Back to search

CVE-2017-5658

Published: Oct 4, 2018

Modified: Sep 16, 2024

PUBLISHED

Description

The statistics generator in Apache Pony Mail 0.7 to 0.9 was found to be returning timestamp data without proper authorization checks. This could lead to derived information disclosure on private lists about the timing of specific email subjects or text bodies, though without disclosing the content itself. As this was primarily used as a caching feature for faster loading times, the caching was disabled by default to prevent this. Users using 0.9 should upgrade to 0.10 to address this issue.

VendorProductVersions

Apache Software Foundation

Apache Pony Mail

affected
0.7 to 0.9 (incubating)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now