7.5
CVSSv2

CVE-2019-18928

Published: 15/11/2019 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cyrus IMAP 2.5.x prior to 2.5.14 and 3.x prior to 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cyrus imap

fedoraproject fedora 30

fedoraproject fedora 31

debian debian linux 9.0

Vendor Advisories

Synopsis Moderate: cyrus-imapd security update Type/Severity Security Advisory: Moderate Topic An update for cyrus-imapd is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base s ...