Back to search
CVE-2019-18928
Published: Nov 15, 2019
Modified: Aug 5, 2024
PUBLISHED
Description
Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
FEDORA-2019-393e1cef4d
vendor-advisory
x_refsource_FEDORA
FEDORA-2019-03be160f9c
vendor-advisory
x_refsource_FEDORA
[debian-lts-announce] 20220619 [SECURITY] [DLA 3052-1] cyrus-imapd security update
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now