PT-2025-40955 · Dovecot+1 · Dovecot Imap Server+1
Published
2025-10-05
·
Updated
2025-12-10
·
CVE-2025-30189
CVSS v3.1
7.4
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Dovecot IMAP Server versions 2.4.0 through 2.4.1
Description
When cache is enabled, some passdb/userdb drivers incorrectly cache all users with the same cache key, leading to incorrect cached information being used. After a successful cached login, all subsequent logins are treated as the same user. This issue affects systems using oauth2 passdb, passwd passdb, userdb, or passwd userdb.
Recommendations
Upgrade to Dovecot IMAP Server version 2.4.2 or later.
Disable auth cache globally or for the impacted passdb/userdb drivers.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dovecot Imap Server
Suse