Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fx6f-5qgf-9fmx

Опубликовано: 27 мар. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.7

Описание

Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for any user and user enumeration. Do not clear auth_username_chars. If this is not possible, install latest fixed version. No publicly available exploits are known.

Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for any user and user enumeration. Do not clear auth_username_chars. If this is not possible, install latest fixed version. No publicly available exploits are known.

EPSS

Процентиль: 33%
0.00395
Низкий

7.7 High

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 7.7
ubuntu
5 месяцев назад

Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for any user and user enumeration. Do not clear auth_username_chars. If this is not possible, install latest fixed version. No publicly available exploits are known.

CVSS3: 7.7
redhat
5 месяцев назад

Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for any user and user enumeration. Do not clear auth_username_chars. If this is not possible, install latest fixed version. No publicly available exploits are known.

CVSS3: 7.7
nvd
5 месяцев назад

Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for any user and user enumeration. Do not clear auth_username_chars. If this is not possible, install latest fixed version. No publicly available exploits are known.

CVSS3: 7.7
debian
5 месяцев назад

Dovecot SQL based authentication can be bypassed when auth_username_ch ...

suse-cvrf
4 месяца назад

Security update for dovecot24

EPSS

Процентиль: 33%
0.00395
Низкий

7.7 High

CVSS3

Дефекты

CWE-89