CVE-2022-30550

    Dashboard / Vulnerabilities / CVE-2022-30550

    CVE-2022-30550

    Published: 17 Jul 2022Last Modified: 12 Aug 2026

    Summary:

    Details: An issue was discovered in the auth component in Dovecot 2.2 and 2.3 before 2.3.20. When two passdb configuration entries exist with the same driver and args settings, incorrect username_filter and mechanism settings can be applied to passdb definitions. These incorrectly applied settings can lead to an unintended security configuration and can permit privilege escalation in certain configurations. The documentation does not advise against the use of passdb definitions that have the same driver and args settings. One such configuration would be where an administrator wishes to use the same PAM configuration or passwd file for both normal and master users but use the username_filter setting to restrict which of the users is able to be a master user.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- c8b89eb9968980589904a58e8bd72fc8c00039be

    Affected versions

    2.2
    2.2.20
    2.2.20.rc1
    2.2.19
    2.2.19.rc2
    2.2.19.rc1
    2.2.18
    2.2.17
    2.2.17.rc2
    2.2.17.rc1
    2.2.16
    2.2.16.rc1
    2.2.15
    2.2.14
    2.2.14.rc1
    2.2.13
    2.2.13.rc1
    2.2.12
    2.2.11
    2.2.10
    2.2.9
    2.2.8
    2.2.7
    2.2.6
    2.2.5
    2.2.4
    2.2.3
    2.2.2
    2.2.1
    2.2.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2022-30550 | CVE-DB