PT-2019-15720 · Cyrus+5 · Cyrus Imap+5

Published

2019-11-15

·

Updated

2025-04-04

·

CVE-2019-18928

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cyrus IMAP versions 2.5.x through 2.5.13 Cyrus IMAP versions 3.x through 3.0.11
Description The issue allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection.
Recommendations For Cyrus IMAP versions 2.5.x through 2.5.13, update to version 2.5.14 or later. For Cyrus IMAP versions 3.x through 3.0.11, update to version 3.0.12 or later.

Fix

Related Identifiers

ALT-PU-2019-3147
ALT-PU-2019-3158
CESA-2020_4655
CVE-2019-18928
DLA-3052-1
OPENSUSE-SU-2025:14968-1
RHSA-2020:4655
RHSA-2020_4655
USN-7224-1

Affected Products

Alt Linux
Centos
Cyrus Imap
Linuxmint
Red Hat
Ubuntu