8.8
CVSSv3

CVE-2022-30550

Published: 17/07/2022 Updated: 12/01/2024
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

An issue exists in the auth component in Dovecot 2.2 and 2.3 prior to 2.3.20. When two passdb configuration entries exist with the same driver and args settings, incorrect username_filter and mechanism settings can be applied to passdb definitions. These incorrectly applied settings can lead to an unintended security configuration and can permit privilege escalation in certain configurations. The documentation does not advise against the use of passdb definitions that have the same driver and args settings. One such configuration would be where an administrator wishes to use the same PAM configuration or passwd file for both normal and master users but use the username_filter setting to restrict which of the users is able to be a master user.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dovecot dovecot

dovecot dovecot 2.2

debian debian linux 10.0

Vendor Advisories

Debian Bug report logs - #1016351 dovecot: CVE-2022-30550 Package: src:dovecot; Maintainer for src:dovecot is Dovecot Maintainers <dovecot@packagesdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Fri, 29 Jul 2022 20:51:01 UTC Severity: grave Tags: pending, security Reply or subscribe to this ...
Synopsis Moderate: dovecot security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for dovecot is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a se ...
Synopsis Moderate: dovecot security and enhancement update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for dovecot is now available for Red Hat Enterprise Linux 9Red Hat Product Security has rated this updat ...
An issue was discovered in the auth component in Dovecot 22 and 23 before 2320 When two passdb configuration entries exist with the same driver and args settings, incorrect username_filter and mechanism settings can be applied to passdb definitions These incorrectly applied settings can lead to an unintended security configuration and can per ...
Severity Unknown Remote Unknown Type Unknown Description AVG-2777 dovecot 23191-1 2320-1 Unknown Vulnerable ...