CVE-2019-20790Authentication Bypass by Spoofing in Opendmarc

Severity
9.8CRITICALNVD
EPSS
0.2%
top 51.87%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 27
Latest updateMay 24

Description

OpenDMARC through 1.3.2 and 1.4.x, when used with pypolicyd-spf 2.0.2, allows attacks that bypass SPF and DMARC authentication in situations where the HELO field is inconsistent with the MAIL FROM field.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages4 packages

debiandebian/opendmarc< opendmarc 1.4.0~beta1+dfsg-4 (bookworm)
Debiantrusteddomain/opendmarc< 1.4.0~beta1+dfsg-4+3
NVDtrusteddomain/opendmarc1.3.01.3.2+1

Also affects: Fedora 33, 34

🔴Vulnerability Details

2
GHSA
GHSA-6pph-69rg-fpw6: OpenDMARC through 12022-05-24
OSV
CVE-2019-20790: OpenDMARC through 12020-04-27

📋Vendor Advisories

1
Debian
CVE-2019-20790: opendmarc - OpenDMARC through 1.3.2 and 1.4.x, when used with pypolicyd-spf 2.0.2, allows at...2019

💬Community

3
Bugzilla
CVE-2019-20790 CVE-2020-12272 opendmarc: Two vulnerabilities in openDMARC 1.3.2 [epel-all]2020-04-27
Bugzilla
CVE-2019-20790 CVE-2020-12272 opendmarc: Two vulnerabilities in openDMARC 1.3.2 [fedora-all]2020-04-27
Bugzilla
CVE-2020-12272 CVE-2019-20790 opendmarc: Two vulnerabilities in openDMARC 1.3.22020-04-27
CVE-2019-20790 — Authentication Bypass by Spoofing | cvebase