CVE Vulnerabilities

CVE-2019-20790

Authentication Bypass by Spoofing

Published: Apr 27, 2020 | Modified: Nov 07, 2023
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

OpenDMARC through 1.3.2 and 1.4.x, when used with pypolicyd-spf 2.0.2, allows attacks that bypass SPF and DMARC authentication in situations where the HELO field is inconsistent with the MAIL FROM field.

Weakness

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

Affected Software

Name Vendor Start Version End Version
Opendmarc Trusteddomain 1.3.0 (including) 1.3.2 (including)
Opendmarc Ubuntu bionic *
Opendmarc Ubuntu eoan *
Opendmarc Ubuntu groovy *
Opendmarc Ubuntu hirsute *
Opendmarc Ubuntu impish *
Opendmarc Ubuntu kinetic *
Opendmarc Ubuntu lunar *
Opendmarc Ubuntu mantic *
Opendmarc Ubuntu trusty *
Opendmarc Ubuntu xenial *

References