یادآوری: اطلاعات این سامانه از منابع معرفی‌شده گردآوری می‌شود. پیش از هر اقدام فنی، جزئیات را در منبع اصلی بررسی کنید.
متوسط CVSS 6.8 EPSS 2.1% اولویت 34/100

CVE-2022-30550— [Dovecot-news] CVE-2022-30550: افزایش سطح دسترسی در dovecot در صورت استفاده از پایگاه‌های داده‌ی اصلی و غیر اصلی مشابه، امکان‌پذیر است.

When two passdb configuration entries exist in Dovecot configuration, which have the same driver and args settings, the incorrect username_filter and mechanism settings can be applied to passdb definitions. These incorrectly applied settings can lead to an unintended security configuration and can permit privilege escalation with certain configurations involving master user authentication. Dovecot documentation does not advise against the use of passdb definitions which have the same driver and args settings. One such configuration would be where an administrator wishes to use the same pam configuration or passwd file for both normal and master users but use the username_filter setting to restrict which of the users is able to be a master user.

انتشار: 2022-05-06 00:00 آخرین مشاهده داده: 2026-08-28 15:25 1 منبع · 1 رسمیاعتماد متوسط · 58/100
اولویت VulnWatch 34/100 ترکیب سیگنال‌های ریسک موجود
CVSS / EPSS 6.8 / 2.1% شدت فنی / احتمال بهره‌برداری
کیفیت داده 67/100 نیازمند توجه · اعتماد متوسط
تازگی داده قدیمی قدیمی‌تر از ۳۰ روز · 1 منبع
راهنمای اقدام

الان چه کاری باید انجام شود؟

پایش و ارزیابی
EPSS 2.1%سیگنال EPSS پایین‌تر است؛ سایر شاخص‌ها را نیز در تصمیم لحاظ کنید.
کیفیت داده 67/100نیازمند توجه · 1 منبع؛ پیش از تغییر Production منبع اصلی را بررسی کنید.
راهکارراهکار در این صفحه ثبت شده است؛ بخش راهکار پیشنهادی را بررسی کنید.
رفتن به راهکار این راهنمای اقدام، RiskScorer را تغییر نمی‌دهد و جایگزین ارزیابی محیط شما نیست.
اولویت عملیاتی 2.5

چرا این مورد باید بررسی شود؟

این امتیاز مستقل از RiskScorer است و برای مرتب‌سازی اقدام‌های عملیاتی استفاده می‌شود.

Priority22
راهکار اجرایی موجود
01

خلاصه آسیب‌پذیری

When two passdb configuration entries exist in Dovecot configuration, which have the same driver and args settings, the incorrect username_filter and mechanism settings can be applied to passdb definitions. These incorrectly applied settings can lead to an unintended security configuration and can permit privilege escalation with certain configurations involving master user authentication. Dovecot documentation does not advise against the use of passdb definitions which have the same driver and args settings. One such configuration would be where an administrator wishes to use the same pam configuration or passwd file for both normal and master users but use the username_filter setting to restrict which of the users is able to be a master user.
02

توضیحات کامل

[Dovecot-news] CVE-2022-30550: Privilege escalation possible in dovecot when similar master and non-master passdbs are used Aki Tuomi aki.tuomi at dovecot.fi Wed Jul 6 13:54:47 UTC 2022 Next message (by thread): [Dovecot-news] CVE-2022-30550: Privilege escalation possible in dovecot when similar master and non-master passdbs are used Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] Affected product: Dovecot IMAP Server Internal reference: DOV-5320 Vulnerability type: Improper Access Control (CWE-284) Vulnerable version: 2.2 Vulnerable component: submission Report confidence: Confirmed Solution status: Fixed in main Researcher credits: Julian Brook (julezman) Vendor notification: 2022-05-06 CVE reference: CVE-2022-30550 CVSS: 6.8 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N) Vulnerability Details: When two passdb configuration entries exist in Dovecot configuration, which have the same driver and args settings, the incorrect username_filter and mechanism settings can be applied to passdb definitions. These incorrectly applied settings can lead to an unintended security configuration and can permit privilege escalation with certain configurations involving master user authentication. Dovecot documentation does not advise against the use of passdb definitions which have the same driver and args settings. One such configuration would be where an administrator wishes to use the same pam configuration or passwd file for both normal and master users but use the username_filter setting to restrict which of the users is able to be a master user. Risk: If same passwd file or PAM is used for both normal and master users, it is possible for attacker to become master user. Workaround: Always authenticate master users from different source than regular users, e.g. using a separate passwd file. Alternatively, you can use global ACLs to ensure that only legimate master users have priviledged access. Fix: This has been fixed in main branch. See https://github.com/dovecot/core/compare/7bad6a24%5E..a1022072.patch Next message (by thread): [Dovecot-news] CVE-2022-30550: Privilege escalation possible in dovecot when similar master and non-master passdbs are used Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] More information about the Dovecot-news mailing list
✓

راهکار پیشنهادی برای رفع

اقدام پیشنهادی
This has been fixed in main branch. See https://github.com/dovecot/core/compare/7bad6a24%5E..a1022072.patch Next message (by thread): [Dovecot-news] CVE-2022-30550: Privilege escalation possible in dovecot when similar master and non-master passdbs are used
↻

راهکار موقت

Always authenticate master users from different source than regular users, e.g. using a separate passwd file. Alternatively, you can use global ACLs to ensure that only legimate master users have priviledged access.
↺

تاریخچه تغییرات معنادار

فقط تغییرات امنیتی مهم مثل KEV، افزایش شدت/CVSS/EPSS، نسخه‌های درگیر و راهکار ثبت می‌شوند.
تاریخچه معنادار از زمان فعال‌شدن موتور 2.5 ساخته می‌شود.
◎

اعتماد، تازگی و پوشش داده

این شاخص عملیاتی از پوشش منابع، کامل‌بودن رکورد، تازگی داده و اختلاف بین منابع ساخته می‌شود و تضمین صحت نیست.
58/100
اعتماد متوسط اعتماد داده 67/100 نیازمند توجه داده قدیمی وضعیت تازگی قدیمی‌تر از ۳۰ روز تازگی مشاهده 100/100 کامل‌بودن · کامل 52/100 پوشش منابع 1 منبع مرتبط 1 رسمی · 1 سطح ۱ 0 اختلاف بین منابع 0 خلأ کیفیت
Dovecot Security رسمی
CVSS
6.8
شدت
medium
محصول
Dovecot / Dovecot
نسخه درگیر
—
نسخه اصلاح‌شده
—
تاریخ انتشار منبع
2022-05-06
⌁

منبع هر داده

برای فیلدهای اصلی می‌توانید ببینید هر مقدار از کدام منبع ثبت شده است. اختلاف بین منابع پنهان نمی‌شود.
CVSS 1 منبع
Dovecot Securityرسمی
6.8
منبع ↗
توضیحات 1 منبع
Dovecot Securityرسمی
[Dovecot-news] CVE-2022-30550: Privilege escalation possible in dovecot when similar master and non-master passdbs are used Aki Tuomi aki.tuomi at dovecot.fi Wed Jul 6 13:54:47 UTC 2022 Next message (by thread): [Dovecot-news] CVE-2022-30550: Privilege escalation possible in dovecot when similar master and non-master passdbs are used Messages sorted by: [ date ] [ thread ] [ subject ] [ autho...
منبع ↗
اثر 1 منبع
Dovecot Securityرسمی
When two passdb configuration entries exist in Dovecot configuration, which have the same driver and args settings, the incorrect username_filter and mechanism settings can be applied to passdb definitions. These incorrectly applied settings can lead to an unintended security configuration and can permit privilege escalation with certain configurations involving master user authentication. Doveco...
منبع ↗
راهکار 1 منبع
Dovecot Securityرسمی
This has been fixed in main branch. See https://github.com/dovecot/core/compare/7bad6a24%5E..a1022072.patch Next message (by thread): [Dovecot-news] CVE-2022-30550: Privilege escalation possible in dovecot when similar master and non-master passdbs are used
منبع ↗
شدت 1 منبع
Dovecot Securityرسمی
medium
منبع ↗
خلاصه 1 منبع
Dovecot Securityرسمی
When two passdb configuration entries exist in Dovecot configuration, which have the same driver and args settings, the incorrect username_filter and mechanism settings can be applied to passdb definitions. These incorrectly applied settings can lead to an unintended security configuration and can permit privilege escalation with certain configurations involving master user authentication. Doveco...
منبع ↗
عنوان 1 منبع
Dovecot Securityرسمی
[Dovecot-news] CVE-2022-30550: Privilege escalation possible in dovecot when similar master and non-master passdbs are used
منبع ↗
راهکار موقت 1 منبع
Dovecot Securityرسمی
Always authenticate master users from different source than regular users, e.g. using a separate passwd file. Alternatively, you can use global ACLs to ensure that only legimate master users have priviledged access.
منبع ↗
↗

منابع و مراجع