PT-2022-3492 · Dovecot+10 · Dovecot+10
Julezman
+1
·
Published
2022-07-06
·
Updated
2024-10-15
·
CVE-2022-30550
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dovecot versions 2.2 through 2.3.19
Description
An issue in the auth component of Dovecot can lead to an unintended security configuration, permitting privilege escalation in certain configurations. This occurs when two passdb configuration entries exist with the same driver and args settings, causing incorrect
username filter and mechanism settings to be applied to passdb definitions. The documentation does not advise against using passdb definitions with the same driver and args settings, which can lead to configurations where an administrator uses the same PAM configuration or passwd file for both normal and master users but attempts to restrict which users can be master users using the username filter setting.Recommendations
For Dovecot versions 2.2 through 2.3.19, update to version 2.3.20 or later to resolve the issue.
As a temporary workaround, consider reviewing and modifying passdb configuration entries to ensure that no two entries have the same driver and args settings, and adjust the
username filter and mechanism settings accordingly to prevent unintended security configurations.Fix
Improper Access Control
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Astra Linux
Centos
Dovecot
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu