Vulnerability record · CVE-2022-30550 · published 17 July 2022
CVE-2022-30550: Dovecot improper authentication vulnerability
Dovecot · Dovecot
An issue was discovered in the auth component in Dovecot 2.2 and 2.3 before 2.3.20. When two passdb configuration entries exist with the same driver and args settings, incorrect username_filter and mechanism settings can be applied to passdb definitions. These incorrectly applied settings can lead to an unintended security configuration and can permit privilege escalation in certain configurations. The documentation does not advise against the use of passdb definitions that have the same driver and args settings. One such configuration would be where an administrator wishes to use the same PAM configuration or passwd file for both normal and master users but use the username_filter setting to restrict which of the users is able to be a master user.
Description
An issue was discovered in the auth component in Dovecot 2.2 and 2.3 before 2.3.20. When two passdb configuration entries exist with the same driver and args settings, incorrect username_filter and mechanism settings can be applied to passdb definitions. These incorrectly applied settings can lead to an unintended security configuration and can permit privilege escalation in certain configurations. The documentation does not advise against the use of passdb definitions that have the same driver and args settings. One such configuration would be where an administrator wishes to use the same PAM configuration or passwd file for both normal and master users but use the username_filter setting to restrict which of the users is able to be a master user.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://dovecot.org/security | Vendor Advisory |
| https://lists.debian.org/debian-lts-announce/2022/09/msg00032.html | Mailing ListThird Party Advisory |
| https://security.gentoo.org/glsa/202310-19 | Third Party Advisory |
| https://www.dovecot.org/download/ | Product |
| https://www.openwall.com/lists/oss-security/2022/07/08/1 | Mailing ListPatchThird Party Advisory |
| https://dovecot.org/security | Vendor Advisory |
| https://lists.debian.org/debian-lts-announce/2022/09/msg00032.html | Mailing ListThird Party Advisory |
| https://security.gentoo.org/glsa/202310-19 | Third Party Advisory |
| https://www.dovecot.org/download/ | Product |
| https://www.openwall.com/lists/oss-security/2022/07/08/1 | Mailing ListPatchThird Party Advisory |
Track CVE-2022-30550 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-30550), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.