Horizon Alert
Summary of the vulnerability and why it matters
This advisory concerns a critical vulnerability in Mailu, an email server solution. The issue allows unauthenticated remote attackers to bypass authentication by spoofing a trusted proxy identity. This could potentially lead to unauthorized access to email server functionalities. The main concern is confirming if Mailu is deployed and if this specific authentication bypass configuration is in use.
- Authentication bypass possible in Mailu email servers.
- Attackers can impersonate trusted proxies remotely.
- Confirm Mailu deployment and proxy configuration relevance.
Attack Path
How an attacker could exploit the issue
An attacker could exploit this vulnerability by sending a specially crafted request to a Mailu mail server. If the server is configured with `PROXY_AUTH_WHITELIST` but not `REAL_IP_HEADER`, the attacker can spoof a trusted proxy's identity by controlling the `X-Forwarded-By` header. This bypasses authentication, allowing the attacker to gain unauthorized access.
- Server exposed to the internet.
- Spoofed `X-Forwarded-By` header.
- Unauthenticated remote access.
Live Threat
Current exploitation, exposure, and threat context
When Mailu is deployed with specific proxy configurations, an unauthenticated remote attacker could impersonate a trusted proxy. This could allow them to bypass authentication mechanisms, potentially affecting the confidentiality and integrity of the mail server's operations and data.
- Mail server authentication.
- Spoofing proxy identity to bypass checks.
- Unauthorized access to mail server functions.
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability in Mailu, a Docker-based mail server, impacts deployments using `PROXY_AUTH_WHITELIST` without `REAL_IP_HEADER` configured. The first practical step is to identify all Mailu instances, determine their reachability and business criticality, and locate the accountable owner before planning remediation.
- Platform or application owners should manage the fix.
- Verify `PROXY_AUTH_WHITELIST` and `REAL_IP_HEADER` settings.
- Plan upgrades during the next maintenance window.