The vulnerability found in php-horde-turba due to insufficient validation of the HTTP request origin. The vulnerability can be exploited by an user of a Horde instance or a remote unauthenticated attacker can trick a victim to open a specially crafted mail to execute arbitrary code on the underlying server. https://blog.sonarsource.com/horde-webmail-rce-via-email/ https://github.com/horde/turba/pull/7 https://lists.horde.org/archives/horde/Week-of-Mon-20220530/059220.html
Created php-horde-turba tracking bugs for this issue: Affects: epel-all [bug 2093190] Affects: fedora-all [bug 2093189]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.