CVE-2019-20790: Critical severity opendmarc vulnerability
Published Apr 27, 2020
·Updated
OpenDMARC through 1.3.2 and 1.4.x, when used with pypolicyd-spf 2.0.2, allows attacks that bypass SPF and DMARC authentication in situations where the HELO field is inconsistent with the MAIL FROM field.
Affected Software
5 affected components
Trusteddomain Opendmarc>=1.3.0<=1.3.2
Trusteddomain Opendmarc=1.4.0
Pypolicyd-spf Project Pypolicyd-spf=2.0.2
Fedoraproject Fedora=33
Fedoraproject Fedora=34
Event History
Apr 27, 2020
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is CVE-2019-20790?
CVE-2019-20790 is a vulnerability in OpenDMARC through 1.3.2 and 1.4.x, when used with pypolicyd-spf 2.0.2, that allows attacks to bypass SPF and DMARC authentication.
2
How does CVE-2019-20790 affect Trusteddomain Opendmarc?
Trusteddomain Opendmarc versions 1.3.0 through 1.3.2 are affected by CVE-2019-20790.
3
Which version of Pypolicyd-spf is affected by CVE-2019-20790?
Pypolicyd-spf version 2.0.2 is affected by CVE-2019-20790.
4
Is Fedora version 33 affected by CVE-2019-20790?
Yes, Fedora version 33 is affected by CVE-2019-20790.
5
What is the severity of CVE-2019-20790?
CVE-2019-20790 is considered critical with a severity value of 9.8.