Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-30189

Опубликовано: 31 окт. 2025
Источник: debian
EPSS Низкий

Описание

When cache is enabled, some passdb/userdb drivers incorrectly cache all users with same cache key, causing wrong cached information to be used for these users. After cached login, all subsequent logins are for same user. Install fixed version or disable caching either globally or for the impacted passdb/userdb drivers. No publicly available exploits are known.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
dovecotfixed1:2.4.1+dfsg1-7package
dovecotnot-affectedbookwormpackage
dovecotnot-affectedbullseyepackage

Примечания

  • Introduced by: https://github.com/dovecot/core/commit/2e298e7ee98b6df61cf85117f000290d60a473b8 (2.4.1)

  • Fixed by: https://github.com/dovecot/core/commit/a70ce7d3e2f983979e971414c5892c4e30197231

  • Regression: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0001.html#cve-2025-30189-v2-4-regression-auth-cache-broken-with-several-passdb-userdb

EPSS

Процентиль: 44%
0.0054
Низкий

Связанные уязвимости

CVSS3: 7.4
ubuntu
10 месяцев назад

When cache is enabled, some passdb/userdb drivers incorrectly cache all users with same cache key, causing wrong cached information to be used for these users. After cached login, all subsequent logins are for same user. Install fixed version or disable caching either globally or for the impacted passdb/userdb drivers. No publicly available exploits are known.

CVSS3: 7.4
nvd
10 месяцев назад

When cache is enabled, some passdb/userdb drivers incorrectly cache all users with same cache key, causing wrong cached information to be used for these users. After cached login, all subsequent logins are for same user. Install fixed version or disable caching either globally or for the impacted passdb/userdb drivers. No publicly available exploits are known.

suse-cvrf
10 месяцев назад

Security update for dovecot24

CVSS3: 7.4
github
10 месяцев назад

When cache is enabled, some passdb/userdb drivers incorrectly cache all users with same cache key, causing wrong cached information to be used for these users. After cached login, all subsequent logins are for same user. Install fixed version or disable caching either globally or for the impacted passdb/userdb drivers. No publicly available exploits are known.

EPSS

Процентиль: 44%
0.0054
Низкий