2024-07

mailcow/mailcow-dockerized2024-07Aug 5, 2024by FreddleSpl0it

AI Summary

Security update fixing CVEs for 2FA bypass and XSS vulnerabilities.

Key Highlights

  • CVE-2024-41958: Two-Factor Authentication (2FA) Bypass Vulnerability
  • CVE-2024-41959: XSS Vulnerability via API Logs
  • CVE-2024-41960: XSS Vulnerability via Relay Hosts Configuration

New Features

  • Security patches for DMARC handling

Full Release Notes

⚠️ Vulnerabilities fixed⚠️
---------------------------------
CVE-2024-41958 - Two-Factor Authentication (2FA) Bypass Vulnerability
CVE-2024-41959 - XSS Vulnerability via API Logs
CVE-2024-41960 - XSS Vulnerability via Relay Hosts Configuration

## What's Changed
* Do not add MAILCOW_WHITE on failed DMARC by @dragoangel in https://github.com/mailcow/mailcow-dockerized/pull/5971
* [Postfix] update postscreen_access.cidr by @milkmaker in https://github.com/mailcow/mailcow-dockerized/pull/5974
* Security fixes by @FreddleSpl0it in https://github.com/mailcow/mailcow-dockerized/pull/5976


**Full Changelog**: https://github.com/mailcow/mailcow-dockerized/compare/2024-06c...2024-07