CVE Vulnerabilities

CVE-2020-24386

Published: Jan 04, 2021 | Modified: Nov 07, 2023
CVSS 3.x
6.8
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
CVSS 2.x
4.9 MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:N
RedHat/V2
RedHat/V3
6.8 MODERATE
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Ubuntu
MEDIUM

An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, an authenticated attacker can trigger unhibernation via attacker-controlled parameters, leading to access to other users email messages (and path disclosure).

Affected Software

Name Vendor Start Version End Version
Dovecot Dovecot 2.2.26 (including) 2.3.13 (excluding)
Red Hat Enterprise Linux 8 RedHat dovecot-1:2.3.8-9.el8 *
Dovecot Ubuntu bionic *
Dovecot Ubuntu devel *
Dovecot Ubuntu focal *
Dovecot Ubuntu groovy *
Dovecot Ubuntu trusty *
Dovecot Ubuntu upstream *

References