CVE-2025-30189
🟡 Monitoruj
Błąd w mechanizmie cache w passdb/userdb powoduje błędne logowanie różnych użytkowników.
CVSS
7.4
EPSS
0.6%
Exploit
none
Vendor
Opis źródłowy (NVD)
When cache is enabled, some passdb/userdb drivers incorrectly cache all users with same cache key, causing wrong cached information to be used for these users. After cached login, all subsequent logins are for same user. Install fixed version or disable caching either globally or for the impacted passdb/userdb drivers. No publicly available exploits are known.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 7.4 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.6% |
| Opublikowano (NVD) | 2025-10-31 09:15:47 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-07 21:10:00 UTC |
Referencje
- https://documentation.open-xchange.com/dovecot/security/advisories/csaf/2026/oxdc-adv-2026-0001.json ([email protected])
- http://seclists.org/fulldisclosure/2025/Oct/29 (af854a3a-2127-422b-91ae-364da2661108)
- http://www.openwall.com/lists/oss-security/2025/10/29/4 (af854a3a-2127-422b-91ae-364da2661108)