VulnerabilityModified
CVE-2020-24386
By using IMAP IDLE, an authenticated attacker can trigger unhibernation via attacker-controlled parameters, leading to access to other users' email messages (and path disclosure).
MEDIUM 6.8EPSS 2.75%
Does this matter?
Lower severity and a low EPSS score (2.75%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, an authenticated attacker can trigger unhibernation via attacker-controlled parameters, leading to access to other users' email messages (and path disclosure).
- CVSS 3.1
- 6.8 MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
- EPSS
- 2.75% probability · 85th percentile
- CISA KEV
- Not listed
- Affected
- dovecot/dovecot · debian/debian linux · fedoraproject/fedora
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/160842/Dovecot-2.3.11.3-Access-Bypass.htmlMailing List, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2021/Jan/18Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2021/01/04/4Mailing List, Third Party Advisory
- https://doc.dovecot.org/configuration_manual/hibernation/Vendor Advisory
- https://dovecot.org/pipermail/dovecot-news/2021-January/000450.htmlMailing List, Vendor Advisory
- https://dovecot.org/securityVendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GXDKFLOCUP7I4ELGQ2F4P5TGC6NXMYV7/
- https://security.gentoo.org/glsa/202101-01Third Party Advisory
- https://www.debian.org/security/2021/dsa-4825Third Party Advisory
- http://packetstormsecurity.com/files/160842/Dovecot-2.3.11.3-Access-Bypass.htmlMailing List, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2021/Jan/18Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2021/01/04/4Mailing List, Third Party Advisory
- https://doc.dovecot.org/configuration_manual/hibernation/Vendor Advisory
- https://dovecot.org/pipermail/dovecot-news/2021-January/000450.htmlMailing List, Vendor Advisory
- https://dovecot.org/securityVendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GXDKFLOCUP7I4ELGQ2F4P5TGC6NXMYV7/
- https://security.gentoo.org/glsa/202101-01Third Party Advisory
- https://www.debian.org/security/2021/dsa-4825Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.