MEDIUM🇵🇱 Wersja polska

CVE-2017-5658

CVSS 5.3v3.0pub. 2018-10-04upd. 2024-11-21

The statistics generator in Apache Pony Mail 0.7 to 0.9 was found to be returning timestamp data without proper authorization checks. This could lead to derived information disclosure on private lists about the timing of specific email subjects or text bodies, though without disclosing the content itself. As this was primarily used as a caching feature for faster loading times, the caching was disabled by default to prevent this. Users using 0.9 should upgrade to 0.10 to address this issue.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
  • Apache Pony Mail

    APP
    Apache
    0.7 – 0.9
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-41873CRITICAL9.8PL ✓same product

HTTP Request Smuggling w Apache Pony Mail — przejęcie konta admina

CVE-2016-4460CRITICAL9.8PL ✓same product

Apache Pony Mail — ominięcie uwierzytelnienia (Auth Bypass)

CVE-2019-0218MEDIUM6.1same product

A vulnerability was discovered wherein a specially crafted URL could enable reflected XSS via JavaScript in th...

CVE-2025-24813CRITICAL9.8⚠ KEVPL ✓same vendor

Apache Tomcat: Path Equivalence prowadzący do RCE i ujawnienia danych

CVE-2024-38856CRITICAL9.8⚠ KEVPL ✓same vendor

Apache OFBiz — nieautoryzowane wykonanie kodu przez błędną autoryzację