Описание
When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP injection attacks when used in authentication. Avoid using safe filter until on fixed version. No publicly available exploits are known.
A flaw was found in Dovecot. When the safe filter is used with variable expansion, subsequent pipelines on the same string are incorrectly interpreted as safe, allowing unsafe data to be unescaped. This can enable SQL (Structured Query Language) or LDAP (Lightweight Directory Access Protocol) injection attacks when used in authentication, potentially leading to unauthorized access or information disclosure.
Отчет
This issue is classified as Important severity primarily because: Exploitation requires a specific configuration where the safe filter is used in combination with variable expansion and subsequent pipelines on the same string during the authentication process. Successfully bypassing the safe filter allows unsafe data to be unescaped, enabling an attacker to execute SQL or LDAP injection attacks, which can lead directly to unauthorized access and significant information disclosure.
Меры по смягчению последствий
To mitigate this issue, avoid using the 'safe filter' feature in Dovecot configurations that involve variable expansion.
Administrators should review Dovecot configuration files, typically found in /etc/dovecot/conf.d/, to identify and disable or modify any configurations that utilize the safe filter with variable expansion.
A restart of the Dovecot service is necessary for these changes to take effect and may impact services relying on this feature.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | dovecot | Not affected | ||
| Red Hat Enterprise Linux 6 | dovecot | Out of support scope | ||
| Red Hat Enterprise Linux 8 | dovecot | Not affected | ||
| Red Hat Enterprise Linux 9 | dovecot | Not affected |
Показывать по
Дополнительная информация
Статус:
7.4 High
CVSS3
Связанные уязвимости
When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP injection attacks when used in authentication. Avoid using safe filter until on fixed version. No publicly available exploits are known.
When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP injection attacks when used in authentication. Avoid using safe filter until on fixed version. No publicly available exploits are known.
When safe filter is used with variable expansion, all following pipeli ...
When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP injection attacks when used in authentication. Avoid using safe filter until on fixed version. No publicly available exploits are known.
7.4 High
CVSS3