Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-24031

Опубликовано: 27 мар. 2026
Источник: ubuntu
Приоритет: medium
CVSS3: 7.7

Описание

Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for any user and user enumeration. Do not clear auth_username_chars. If this is not possible, install latest fixed version. No publicly available exploits are known.

РелизСтатусПримечание
devel

pending

1:2.4.2+dfsg1-3ubuntu2
esm-infra-legacy/trusty

not-affected

code not present
esm-infra/bionic

not-affected

code not present
esm-infra/focal

not-affected

code not present
esm-infra/xenial

not-affected

code not present
jammy

not-affected

code not present
noble

not-affected

code not present
questing

released

1:2.4.1+dfsg1-5ubuntu4.1
upstream

released

2.4.3

Показывать по

7.7 High

CVSS3

Связанные уязвимости

CVSS3: 7.7
redhat
6 дней назад

Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for any user and user enumeration. Do not clear auth_username_chars. If this is not possible, install latest fixed version. No publicly available exploits are known.

CVSS3: 7.7
nvd
6 дней назад

Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for any user and user enumeration. Do not clear auth_username_chars. If this is not possible, install latest fixed version. No publicly available exploits are known.

CVSS3: 7.7
debian
6 дней назад

Dovecot SQL based authentication can be bypassed when auth_username_ch ...

CVSS3: 7.7
github
6 дней назад

Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for any user and user enumeration. Do not clear auth_username_chars. If this is not possible, install latest fixed version. No publicly available exploits are known.

7.7 High

CVSS3