Authentication Bypass by Spoofing in OpenDMARC - CVE-2019-20790
Published: April 30, 2021
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists in OpenDMARC when used with pypolicyd-spf 2.0.2 when processing headers added by previous SPF filters. A remote attacker can bypass SPF and DMARC authentication in situations where the HELO field is inconsistent with the MAIL FROM field.
Affected software
Arch Linux
Fedora
opendmarc
How to mitigate CVE-2019-20790
opendmarc - addressed in versions 1.4.1-1.el7, 1.4.1-1.el8, 1.4.1-1.fc33, 1.4.1-1.fc34
External References
- https://bugs.launchpad.net/pypolicyd-spf/+bug/1838816
- https://sourceforge.net/p/opendmarc/tickets/235/
- https://www.usenix.org/system/files/sec20fall_chen-jianjun_prepub_0.pdf
- https://github.com/trusteddomainproject/OpenDMARC/releases/tag/rel-opendmarc-1-4-1
- https://github.com/trusteddomainproject/OpenDMARC/blob/master/SECURITY/CVE-2019-20790