CVE-2017-5658

Severity
5.3MEDIUM
EPSS
0.9%
top 24.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 4
Latest updateMay 14

Description

The statistics generator in Apache Pony Mail 0.7 to 0.9 was found to be returning timestamp data without proper authorization checks. This could lead to derived information disclosure on private lists about the timing of specific email subjects or text bodies, though without disclosing the content itself. As this was primarily used as a caching feature for faster loading times, the caching was disabled by default to prevent this. Users using 0.9 should upgrade to 0.10 to address this issue.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

CVEListV5apache_software_foundation/apache_pony_mail0.7 to 0.9 (incubating)
NVDapache/pony_mail0.70.9

🔴Vulnerability Details

2
GHSA
GHSA-hx6p-r9cg-jvwv: The statistics generator in Apache Pony Mail 02022-05-14
CVEList
CVE-2017-5658: The statistics generator in Apache Pony Mail 02018-10-04
CVE-2017-5658 (MEDIUM CVSS 5.3) | The statistics generator in Apache | cvebase.io