PT-2026-83069 · Dovecot · Dovecot
CVSS v3.1
3.1
Low
| Vector | AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
dovecot versions prior to 2.4.5-1.1
Description
The comparison process for the doveadm password and API key is not fully timing safe. This allows an attacker on the same network as the doveadm service to determine the length of the configured secret by making repeated requests and measuring response timing. While the secret value itself is not disclosed, knowing its length reduces the effort required to guess it.
Recommendations
Update to version 2.4.5-1.1.
Restrict network access to the doveadm service to trusted clients.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dovecot