CVE Vulnerabilities

CVE-2019-18928

Published: Nov 15, 2019 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
7.4 MODERATE
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection.

Affected Software

NameVendorStart VersionEnd Version
ImapCyrus2.5.0 (including)2.5.14 (excluding)
ImapCyrus3.0.0 (including)3.0.12 (excluding)
Red Hat Enterprise Linux 8RedHatcyrus-imapd-0:3.0.7-19.el8*
Cyrus-imapdUbuntubionic*
Cyrus-imapdUbuntudevel*
Cyrus-imapdUbuntudisco*
Cyrus-imapdUbuntueoan*
Cyrus-imapdUbuntuesm-apps/bionic*
Cyrus-imapdUbuntuesm-apps/focal*
Cyrus-imapdUbuntuesm-apps/jammy*
Cyrus-imapdUbuntuesm-apps/noble*
Cyrus-imapdUbuntufocal*
Cyrus-imapdUbuntugroovy*
Cyrus-imapdUbuntuhirsute*
Cyrus-imapdUbuntuimpish*
Cyrus-imapdUbuntujammy*
Cyrus-imapdUbuntukinetic*
Cyrus-imapdUbuntulunar*
Cyrus-imapdUbuntumantic*
Cyrus-imapdUbuntunoble*
Cyrus-imapdUbuntuoracular*
Cyrus-imapdUbuntutrusty*
Cyrus-imapdUbuntuupstream*

References