Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jp3r-27f3-r855

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.8

Описание

An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, an authenticated attacker can trigger unhibernation via attacker-controlled parameters, leading to access to other users' email messages (and path disclosure).

An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, an authenticated attacker can trigger unhibernation via attacker-controlled parameters, leading to access to other users' email messages (and path disclosure).

EPSS

Процентиль: 70%
0.00626
Низкий

6.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.8
ubuntu
около 5 лет назад

An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, an authenticated attacker can trigger unhibernation via attacker-controlled parameters, leading to access to other users' email messages (and path disclosure).

CVSS3: 6.8
redhat
около 5 лет назад

An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, an authenticated attacker can trigger unhibernation via attacker-controlled parameters, leading to access to other users' email messages (and path disclosure).

CVSS3: 6.8
nvd
около 5 лет назад

An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, an authenticated attacker can trigger unhibernation via attacker-controlled parameters, leading to access to other users' email messages (and path disclosure).

CVSS3: 6.8
debian
около 5 лет назад

An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, ...

suse-cvrf
около 5 лет назад

Security update for dovecot22

EPSS

Процентиль: 70%
0.00626
Низкий

6.8 Medium

CVSS3