Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-24386

Опубликовано: 04 янв. 2021
Источник: redhat
CVSS3: 6.8
EPSS Низкий

Описание

An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, an authenticated attacker can trigger unhibernation via attacker-controlled parameters, leading to access to other users' email messages (and path disclosure).

Меры по смягчению последствий

To mitigate this flaw, ensure that imap_hibernate_timeout is set to 0 or not set at all/commented out in both /etc/dovecot/dovecot.conf or /etc/dovecot/conf.d/20-imap.conf.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5dovecotOut of support scope
Red Hat Enterprise Linux 6dovecotOut of support scope
Red Hat Enterprise Linux 7dovecotOut of support scope
Red Hat Enterprise Linux 9dovecotAffected
Red Hat Enterprise Linux 8dovecotFixedRHSA-2021:188718.05.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-138
https://bugzilla.redhat.com/show_bug.cgi?id=1912455dovecot: IMAP hibernation function allows mail access

EPSS

Процентиль: 70%
0.00626
Низкий

6.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.8
ubuntu
около 5 лет назад

An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, an authenticated attacker can trigger unhibernation via attacker-controlled parameters, leading to access to other users' email messages (and path disclosure).

CVSS3: 6.8
nvd
около 5 лет назад

An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, an authenticated attacker can trigger unhibernation via attacker-controlled parameters, leading to access to other users' email messages (and path disclosure).

CVSS3: 6.8
debian
около 5 лет назад

An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, ...

suse-cvrf
около 5 лет назад

Security update for dovecot22

CVSS3: 6.8
github
больше 3 лет назад

An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, an authenticated attacker can trigger unhibernation via attacker-controlled parameters, leading to access to other users' email messages (and path disclosure).

EPSS

Процентиль: 70%
0.00626
Низкий

6.8 Medium

CVSS3