CVE Vulnerabilities

CVE-2020-24386

Published: Jan 04, 2021 | Modified: Nov 21, 2024
CVSS 3.x
6.8
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
CVSS 2.x
4.9 MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:N
RedHat/V2
RedHat/V3
6.8 MODERATE
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, an authenticated attacker can trigger unhibernation via attacker-controlled parameters, leading to access to other users email messages (and path disclosure).

Affected Software

NameVendorStart VersionEnd Version
DovecotDovecot2.2.26 (including)2.3.13 (excluding)
Red Hat Enterprise Linux 8RedHatdovecot-1:2.3.8-9.el8*
DovecotUbuntubionic*
DovecotUbuntudevel*
DovecotUbuntuesm-infra/bionic*
DovecotUbuntuesm-infra/focal*
DovecotUbuntufocal*
DovecotUbuntugroovy*
DovecotUbuntutrusty*
DovecotUbuntuupstream*

References