CVE-2022-30550

HIGH

Dovecot 2.2-2.3 < 2.3.20 - Privilege Escalation via Duplicate Passdb Configuration

Title source: llm
STIX 2.1

Description

An issue was discovered in the auth component in Dovecot 2.2 and 2.3 before 2.3.20. When two passdb configuration entries exist with the same driver and args settings, incorrect username_filter and mechanism settings can be applied to passdb definitions. These incorrectly applied settings can lead to an unintended security configuration and can permit privilege escalation in certain configurations. The documentation does not advise against the use of passdb definitions that have the same driver and args settings. One such configuration would be where an administrator wishes to use the same PAM configuration or passwd file for both normal and master users but use the username_filter setting to restrict which of the users is able to be a master user.

References (5)

Core 5
Core References
Mailing List, Third Party Advisory mailing-list
https://lists.debian.org/debian-lts-announce/2022/09/msg00032.html
Third Party Advisory vendor-advisory
https://security.gentoo.org/glsa/202310-19
Mailing List, Patch, Third Party Advisory
https://www.openwall.com/lists/oss-security/2022/07/08/1

Scores

CVSS v3 8.8
EPSS 0.0031
EPSS Percentile 54.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-287
Status published
Products (3)
debian/debian_linux 10.0
dovecot/dovecot 2.2
dovecot/dovecot 2.3 - 2.4.0
Published Jul 17, 2022
Tracked Since Feb 18, 2026