ZeroHour

CVE-2019-18928

CVSS 3.1
9.8 critical
EPSS
2%p83
Published
()
Modified
Description

Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection.

Vendors
cyrusfedoraprojectdebian
Products
imap, fedora, debian linux
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.