CVE-2019-18928

CRITICAL

Cyrus IMAP <2.5.14, <3.0.12 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection.

References (5)

Core 5
Core References
Patch, Release Notes, Third Party Advisory x_refsource_misc
https://www.cyrusimap.org/imap/download/release-notes/3.0/x/3.0.12.html
Patch, Release Notes, Third Party Advisory x_refsource_misc
https://www.cyrusimap.org/imap/download/release-notes/2.5/x/2.5.14.html
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2022/06/msg00013.html

Scores

CVSS v3 9.8
EPSS 0.0239
EPSS Percentile 82.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (4)
cyrus/imap 2.5.0 - 2.5.14
debian/debian_linux 9.0
fedoraproject/fedora 30
fedoraproject/fedora 31
Published Nov 15, 2019
Tracked Since Feb 18, 2026