PT-2025-40955 · Dovecot+1 · Dovecot Imap Server+1
CVE-2025-30189
·
Publicado
2025-10-05
·
Atualizado
2025-12-10
CVSS v3.1
7.4
Alta
| Vetor | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Dovecot IMAP Server versions 2.4.0 through 2.4.1
Description
When cache is enabled, some passdb/userdb drivers incorrectly cache all users with the same cache key, leading to incorrect cached information being used. After a successful cached login, all subsequent logins are treated as the same user. This issue affects systems using oauth2 passdb, passwd passdb, userdb, or passwd userdb.
Recommendations
Upgrade to Dovecot IMAP Server version 2.4.2 or later.
Disable auth cache globally or for the impacted passdb/userdb drivers.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Dovecot Imap Server
Suse