The Roundcube component of Analogic Poste.io 2.1.6 uses .htaccess to protect the logs/ folder, which is effective with the Apache HTTP Server but is ineffective with nginx. Attackers can read logs via the webmail/logs/sendmail URI.
References
Link Resource
https://bitbucket.org/analogic/mailserver/issues/665/posteio-logs-leak Exploit Issue Tracking Third Party Advisory
https://poste.io/changelog Release Notes Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2019-06-24T13:07:31

Updated: 2019-06-24T13:07:31

Reserved: 2019-06-24T00:00:00


Link: CVE-2019-12938

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2019-06-24T14:15:09.857

Modified: 2019-06-27T17:35:00.247


Link: CVE-2019-12938

JSON object: View

cve-icon Redhat Information

No data.

CWE