Bug 55440 - Forward emails should not happen for a disabled account
Forward emails should not happen for a disabled account
Status: NEW
Product: UCS
Classification: Unclassified
Component: Mail
UCS 5.0
Other All
: P5 normal (vote)
: ---
Assigned To: Mail maintainers
Mail maintainers
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2022-11-18 16:19 CET by office
Modified: 2022-11-18 16:24 CET (History)
0 users

See Also:
What kind of report is it?: Bug Report
What type of bug is this?: ---
Who will be affected by this bug?: 5: Will affect all installed domains
How will those affected feel about the bug?: 2: A Pain – users won’t like this once they notice it
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Max CVSS v3 score:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description office 2022-11-18 16:19:57 CET
In our setup most internal users have an automatic forwarding of their EMails to an external EMAil-Provider. (This is done to bypass local-site connection and use teh EMailhosting  from anywhere in the Internet).
TO archive this each user has his corresponding EMail-Hosting address setup in User-account --> advanced settings --> MAil --> Forward email address (https://docs.software-univention.de/manual/5.0/en/mail/management.html#assignment-of-email-addresses-to-users).

Recently I disabled some user-accounts in UCS and also at EMail-hosing. As some internal services still address these disabled UCS-users I got some bounces from EMAil-hosting. 
So EMAil are still forwarded, even the user is disabled. This seems unintended, AS this way information might get leaked. When forwarding to a not company-controlled EMail-hosting, the use will be able to receive EMAils (used by services, existing EMail-threads or directly) addressed to him on the forwarded address.

I expect that no emails are forwarded for disabled / locked accounts.
Comment 1 office 2022-11-18 16:24:50 CET
In a 1 countermeasure, I manually checked all disabled accounts and removed forward-address