CVE-2019-18928
CRITICALCyrus IMAP <2.5.14, <3.0.12 - Privilege Escalation
Title source: llmDescription
Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection.
References (5)
Core 5
Core References
Patch, Release Notes, Third Party Advisory x_refsource_misc
https://www.cyrusimap.org/imap/download/release-notes/3.0/x/3.0.12.html
Patch, Release Notes, Third Party Advisory x_refsource_misc
https://www.cyrusimap.org/imap/download/release-notes/2.5/x/2.5.14.html
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PHV3TUU53WCKJ3BBRK2EHAF44MSZEFK6/
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LAGKPZDXQ6KRUGQVRAO6N4PCINP6KS5F/
Mailing List, Third Party Advisory mailing-list
x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2022/06/msg00013.html
Scores
CVSS v3
9.8
EPSS
0.0239
EPSS Percentile
82.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
Status
published
Products (4)
cyrus/imap
2.5.0 - 2.5.14
debian/debian_linux
9.0
fedoraproject/fedora
30
fedoraproject/fedora
31
Published
Nov 15, 2019
Tracked Since
Feb 18, 2026