First published: Mon May 10 2021(Updated: )
Cyrus IMAP before 3.2.7, and 3.3.x and 3.4.x before 3.4.1, allows remote authenticated users to bypass intended access restrictions on server annotations and consequently cause replication to stall.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cyrus SASL | <3.2.7 | |
Cyrus SASL | >=3.3.0<3.4.1 | |
Red Hat Fedora | =34 | |
Red Hat Fedora | =35 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-32056 is categorized as a medium severity vulnerability.
To fix CVE-2021-32056, upgrade to Cyrus IMAP version 3.2.7 or 3.4.1 or later.
CVE-2021-32056 affects Cyrus IMAP versions prior to 3.2.7, and versions 3.3.x and 3.4.x prior to 3.4.1.
CVE-2021-32056 allows remote authenticated users to bypass access restrictions, which can stall server replication.
CVE-2021-32056 impacts the Cyrus IMAP Server on various platforms including Fedora versions 34 and 35.