CVE-2021-32056

Related Vulnerabilities: CVE-2021-32056  

Cyrus IMAP before 3.2.7, and 3.3.x and 3.4.x before 3.4.1, allows remote authenticated users to bypass intended access restrictions on server annotations and consequently cause replication to stall.

Description

The MITRE CVE dictionary describes this issue as:

Cyrus IMAP before 3.2.7, and 3.3.x and 3.4.x before 3.4.1, allows remote authenticated users to bypass intended access restrictions on server annotations and consequently cause replication to stall.

Additional Information

  • Bugzilla 1959138: CVE-2021-32056 cyrus-imapd: remote authenticated users could bypass intended access restrictions on certain server annotations
  • CWE-863: Incorrect Authorization
  • FAQ: Frequently asked questions about CVE-2021-32056