microsoft / microsoft/CSS-Exchange
microsoft-exchange-client-access-server-information-disclosure
@lusassl-msft is already working on this.
Since Apr 9, 2024.
- Dominant language
- PowerShell
- Stars
- 1.3k
- Forks
- 395
- Avg merge
- 14h 7m
- Merged PRs (30d)
- 5
Description
Hi
Synopsis
The remote mail server is affected by an information disclosure vulnerability.
Description
The Microsoft Exchange Client Access Server (CAS) is affected by an information disclosure vulnerability. A remote, unauthenticated attacker can exploit this vulnerability to learn the server's internal IP address.
An attacker can send a crafted GET request to the Web Server with an empty host header that would expose internal IP Addresses of the underlying system in the header response.
Please add capability to check url write rule for hiding server internal ip as explained below.
https://www.cyberis.com/article/microsoft-exchange-client-access-server-information-disclosure
Thanks
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Assessment
This issue has not been assessed yet.