CyberRota Analysis
AI-GeneratedCyrus IMAP versions prior to 3.12.4 are vulnerable to a CalDAV/CardDAV multiget bypass, allowing authenticated users with limited access to read unshared calendar events or contacts by manipulating target hrefs in specific REPORT requests. This could lead to unauthorized data exposure, impacting user privacy. Organizations using affected versions should prioritize patching to mitigate potential information leakage.
Original NVD Description
An issue was discovered in Cyrus IMAP before 3.12.4. CalDAV/CardDAV multiget bypasses a per-href ACL. An authenticated DAV user with some shared access to another user's calendar or address book could read even unshared events or contacts by including the target hrefs in a calendar-multiget or addressbook-multiget REPORT.