CVE-2022-39258 is a high-severity vulnerability affecting mailcow mail server suites prior to the 2022-09 update. An unauthenticated attacker can craft a malicious Swagger API template to redirect victims to attacker-controlled sites, potentially leading to the theft of Swagger authorization credentials or other sensitive information through phishing. The vulnerability has a CVSS score of 8.2 (HIGH) due to its network-based attack vector, low complexity, and high impact on confidentiality. While there is no evidence of active exploitation, public exploit code, or significant community discussion, affected organizations should apply the 2022-09 mailcow Mootember Update or remove the Swagger API Documentation as a workaround.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2022-09CPE matchmatch criteria | cpe:2.3:a:mailcow:mailcow\:_dockerized:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.