PT-2022-3492 · Dovecot+10 · Dovecot+10

Julezman

+1

·

Published

2022-07-06

·

Updated

2024-10-15

·

CVE-2022-30550

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dovecot versions 2.2 through 2.3.19
Description An issue in the auth component of Dovecot can lead to an unintended security configuration, permitting privilege escalation in certain configurations. This occurs when two passdb configuration entries exist with the same driver and args settings, causing incorrect username filter and mechanism settings to be applied to passdb definitions. The documentation does not advise against using passdb definitions with the same driver and args settings, which can lead to configurations where an administrator uses the same PAM configuration or passwd file for both normal and master users but attempts to restrict which users can be master users using the username filter setting.
Recommendations For Dovecot versions 2.2 through 2.3.19, update to version 2.3.20 or later to resolve the issue. As a temporary workaround, consider reviewing and modifying passdb configuration entries to ensure that no two entries have the same driver and args settings, and adjust the username filter and mechanism settings accordingly to prevent unintended security configurations.

Fix

Improper Access Control

Improper Authentication

Weakness Enumeration

Related Identifiers

ALSA-2022:7623
ALSA-2022:8208
ALT-PU-2022-2895
ALT-PU-2022-2943
ALT-PU-2022-3255
ALT-PU-2022-3415
ALT-PU-2023-5751
ALT-PU-2024-11395
AZL-10311
AZL-44649
BDU:2022-04273
CESA-2022_7623
CVE-2022-30550
DLA-3122-1
MGASA-2022-0296
OESA-2022-1994
OPENSUSE-SU-2022_2448-1
RHSA-2022:7623
RHSA-2022:8208
RHSA-2022_7623
RHSA-2022_8208
RLSA-2022:7623
RLSA-2022:8208
SUSE-SU-2022:2431-1
SUSE-SU-2022:2432-1
SUSE-SU-2022:2448-1
SUSE-SU-2022:2618-1
SUSE-SU-2022_2431-1
SUSE-SU-2022_2432-1
SUSE-SU-2022_2448-1
SUSE-SU-2022_2618-1
USN-5509-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Dovecot
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu