Логотип exploitDog
bind: "CVE-2022-30550"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2022-30550"

Количество 14

Количество 14

ubuntu логотип

CVE-2022-30550

почти 3 года назад

An issue was discovered in the auth component in Dovecot 2.2 and 2.3 before 2.3.20. When two passdb configuration entries exist with the same driver and args settings, incorrect username_filter and mechanism settings can be applied to passdb definitions. These incorrectly applied settings can lead to an unintended security configuration and can permit privilege escalation in certain configurations. The documentation does not advise against the use of passdb definitions that have the same driver and args settings. One such configuration would be where an administrator wishes to use the same PAM configuration or passwd file for both normal and master users but use the username_filter setting to restrict which of the users is able to be a master user.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2022-30550

почти 3 года назад

An issue was discovered in the auth component in Dovecot 2.2 and 2.3 before 2.3.20. When two passdb configuration entries exist with the same driver and args settings, incorrect username_filter and mechanism settings can be applied to passdb definitions. These incorrectly applied settings can lead to an unintended security configuration and can permit privilege escalation in certain configurations. The documentation does not advise against the use of passdb definitions that have the same driver and args settings. One such configuration would be where an administrator wishes to use the same PAM configuration or passwd file for both normal and master users but use the username_filter setting to restrict which of the users is able to be a master user.

CVSS3: 6.8
EPSS: Низкий
nvd логотип

CVE-2022-30550

почти 3 года назад

An issue was discovered in the auth component in Dovecot 2.2 and 2.3 before 2.3.20. When two passdb configuration entries exist with the same driver and args settings, incorrect username_filter and mechanism settings can be applied to passdb definitions. These incorrectly applied settings can lead to an unintended security configuration and can permit privilege escalation in certain configurations. The documentation does not advise against the use of passdb definitions that have the same driver and args settings. One such configuration would be where an administrator wishes to use the same PAM configuration or passwd file for both normal and master users but use the username_filter setting to restrict which of the users is able to be a master user.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2022-30550

почти 3 года назад

An issue was discovered in the auth component in Dovecot 2.2 and 2.3 b ...

CVSS3: 8.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:2618-1

почти 3 года назад

Security update for dovecot22

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:2448-1

почти 3 года назад

Security update for dovecot23

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:2432-1

почти 3 года назад

Security update for dovecot23

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:2431-1

почти 3 года назад

Security update for dovecot23

EPSS: Низкий
rocky логотип

RLSA-2022:8208

больше 2 лет назад

Moderate: dovecot security and enhancement update

EPSS: Низкий
rocky логотип

RLSA-2022:7623

больше 2 лет назад

Moderate: dovecot security update

EPSS: Низкий
github логотип

GHSA-cch8-vp96-g53m

почти 3 года назад

An issue was discovered in the auth component in Dovecot 2.2 and 2.3 before 2.3.20. When two passdb configuration entries exist with the same driver and args settings, incorrect username_filter and mechanism settings can be applied to passdb definitions. These incorrectly applied settings can lead to an unintended security configuration and can permit privilege escalation in certain configurations. The documentation does not advise against the use of passdb definitions that have the same driver and args settings. One such configuration would be where an administrator wishes to use the same PAM configuration or passwd file for both normal and master users but use the username_filter setting to restrict which of the users is able to be a master user.

CVSS3: 8.8
EPSS: Низкий
oracle-oval логотип

ELSA-2022-8208

больше 2 лет назад

ELSA-2022-8208: dovecot security and enhancement update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2022-7623

больше 2 лет назад

ELSA-2022-7623: dovecot security update (MODERATE)

EPSS: Низкий
redos логотип

ROS-20220714-02

почти 3 года назад

Уязвимость Dovecot

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-30550

An issue was discovered in the auth component in Dovecot 2.2 and 2.3 before 2.3.20. When two passdb configuration entries exist with the same driver and args settings, incorrect username_filter and mechanism settings can be applied to passdb definitions. These incorrectly applied settings can lead to an unintended security configuration and can permit privilege escalation in certain configurations. The documentation does not advise against the use of passdb definitions that have the same driver and args settings. One such configuration would be where an administrator wishes to use the same PAM configuration or passwd file for both normal and master users but use the username_filter setting to restrict which of the users is able to be a master user.

CVSS3: 8.8
0%
Низкий
почти 3 года назад
redhat логотип
CVE-2022-30550

An issue was discovered in the auth component in Dovecot 2.2 and 2.3 before 2.3.20. When two passdb configuration entries exist with the same driver and args settings, incorrect username_filter and mechanism settings can be applied to passdb definitions. These incorrectly applied settings can lead to an unintended security configuration and can permit privilege escalation in certain configurations. The documentation does not advise against the use of passdb definitions that have the same driver and args settings. One such configuration would be where an administrator wishes to use the same PAM configuration or passwd file for both normal and master users but use the username_filter setting to restrict which of the users is able to be a master user.

CVSS3: 6.8
0%
Низкий
почти 3 года назад
nvd логотип
CVE-2022-30550

An issue was discovered in the auth component in Dovecot 2.2 and 2.3 before 2.3.20. When two passdb configuration entries exist with the same driver and args settings, incorrect username_filter and mechanism settings can be applied to passdb definitions. These incorrectly applied settings can lead to an unintended security configuration and can permit privilege escalation in certain configurations. The documentation does not advise against the use of passdb definitions that have the same driver and args settings. One such configuration would be where an administrator wishes to use the same PAM configuration or passwd file for both normal and master users but use the username_filter setting to restrict which of the users is able to be a master user.

CVSS3: 8.8
0%
Низкий
почти 3 года назад
debian логотип
CVE-2022-30550

An issue was discovered in the auth component in Dovecot 2.2 and 2.3 b ...

CVSS3: 8.8
0%
Низкий
почти 3 года назад
suse-cvrf логотип
SUSE-SU-2022:2618-1

Security update for dovecot22

0%
Низкий
почти 3 года назад
suse-cvrf логотип
SUSE-SU-2022:2448-1

Security update for dovecot23

0%
Низкий
почти 3 года назад
suse-cvrf логотип
SUSE-SU-2022:2432-1

Security update for dovecot23

0%
Низкий
почти 3 года назад
suse-cvrf логотип
SUSE-SU-2022:2431-1

Security update for dovecot23

0%
Низкий
почти 3 года назад
rocky логотип
RLSA-2022:8208

Moderate: dovecot security and enhancement update

0%
Низкий
больше 2 лет назад
rocky логотип
RLSA-2022:7623

Moderate: dovecot security update

0%
Низкий
больше 2 лет назад
github логотип
GHSA-cch8-vp96-g53m

An issue was discovered in the auth component in Dovecot 2.2 and 2.3 before 2.3.20. When two passdb configuration entries exist with the same driver and args settings, incorrect username_filter and mechanism settings can be applied to passdb definitions. These incorrectly applied settings can lead to an unintended security configuration and can permit privilege escalation in certain configurations. The documentation does not advise against the use of passdb definitions that have the same driver and args settings. One such configuration would be where an administrator wishes to use the same PAM configuration or passwd file for both normal and master users but use the username_filter setting to restrict which of the users is able to be a master user.

CVSS3: 8.8
0%
Низкий
почти 3 года назад
oracle-oval логотип
ELSA-2022-8208

ELSA-2022-8208: dovecot security and enhancement update (MODERATE)

больше 2 лет назад
oracle-oval логотип
ELSA-2022-7623

ELSA-2022-7623: dovecot security update (MODERATE)

больше 2 лет назад
redos логотип
ROS-20220714-02

Уязвимость Dovecot

0%
Низкий
почти 3 года назад

Уязвимостей на страницу