Vulnerability Description
OpenDMARC through 1.3.2 and 1.4.x, when used with pypolicyd-spf 2.0.2, allows attacks that bypass SPF and DMARC authentication in situations where the HELO field is inconsistent with the MAIL FROM field.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Trusteddomain | Opendmarc | >= 1.3.0, <= 1.3.2 |
| Pypolicyd-Spf Project | Pypolicyd-Spf | 2.0.2 |
| Fedoraproject | Fedora | 33 |
Related Weaknesses (CWE)
References
- https://bugs.launchpad.net/pypolicyd-spf/+bug/1838816ExploitThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://sourceforge.net/p/opendmarc/tickets/235/ExploitThird Party Advisory
- https://www.usenix.org/system/files/sec20fall_chen-jianjun_prepub_0.pdfTechnical DescriptionThird Party Advisory
- https://bugs.launchpad.net/pypolicyd-spf/+bug/1838816ExploitThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://sourceforge.net/p/opendmarc/tickets/235/ExploitThird Party Advisory
- https://www.usenix.org/system/files/sec20fall_chen-jianjun_prepub_0.pdfTechnical DescriptionThird Party Advisory
FAQ
What is CVE-2019-20790?
CVE-2019-20790 is a vulnerability with a CVSS score of 9.8 (CRITICAL). OpenDMARC through 1.3.2 and 1.4.x, when used with pypolicyd-spf 2.0.2, allows attacks that bypass SPF and DMARC authentication in situations where the HELO field is inconsistent with the MAIL FROM fie...
How severe is CVE-2019-20790?
CVE-2019-20790 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-20790?
Check the references section above for vendor advisories and patch information. Affected products include: Trusteddomain Opendmarc, Pypolicyd-Spf Project Pypolicyd-Spf, Fedoraproject Fedora.