PT-2025-40955 · Dovecot+1 · Dovecot Imap Server+1

CVE-2025-30189

·

Publicado

2025-10-05

·

Atualizado

2025-12-10

CVSS v3.1

7.4

Alta

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Dovecot IMAP Server versions 2.4.0 through 2.4.1
Description When cache is enabled, some passdb/userdb drivers incorrectly cache all users with the same cache key, leading to incorrect cached information being used. After a successful cached login, all subsequent logins are treated as the same user. This issue affects systems using oauth2 passdb, passwd passdb, userdb, or passwd userdb.
Recommendations Upgrade to Dovecot IMAP Server version 2.4.2 or later. Disable auth cache globally or for the impacted passdb/userdb drivers.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

AZL-69833
AZL-69835
CVE-2025-30189
DSA-6019-1
OPENSUSE-SU-2025-20113-1
OPENSUSE-SU-2025:15676-1
OPENSUSE-SU-2025:20113-1
SUSE-SU-2025:21159-1
SUSE-SU-2025_21159-1

Produtos afetados

Dovecot Imap Server
Suse