CVE-2021-32056

MEDIUM

Cyrus Imap < 3.2.7 - Incorrect Permission Assignment

Title source: rule
STIX 2.1

Description

Cyrus IMAP before 3.2.7, and 3.3.x and 3.4.x before 3.4.1, allows remote authenticated users to bypass intended access restrictions on server annotations and consequently cause replication to stall.

References (6)

Core 6
Core References
Patch, Release Notes, Vendor Advisory x_refsource_confirm
https://cyrus.topicbox.com/groups/announce/T056901c106ecfce3/cyrus-imap-3-4-1-released
Patch, Release Notes, Vendor Advisory x_refsource_confirm
https://cyrus.topicbox.com/groups/announce/T126392718bc29d6b/cyrus-imap-3-2-7-released
Patch, Release Notes, Vendor Advisory x_refsource_confirm
https://www.cyrusimap.org/imap/download/release-notes/3.4/x/3.4.1.html
Patch, Release Notes, Vendor Advisory x_refsource_confirm
https://www.cyrusimap.org/imap/download/release-notes/3.2/x/3.2.7.html

Scores

CVSS v3 4.3
EPSS 0.0021
EPSS Percentile 43.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Details

CWE
CWE-732
Status published
Products (3)
cyrus/imap < 3.2.7
fedoraproject/fedora 34
fedoraproject/fedora 35
Published May 10, 2021
Tracked Since Feb 18, 2026