cbcvebase.
CVE-2020-28200
published 2021-06-28

CVE-2020-28200: The Sieve engine in Dovecot before 2.3.15 allows Uncontrolled Resource Consumption, as demonstrated by a situation with a complex regular expression for the…

PriorityP421medium4.3CVSS 3.1
AVNACLPRLUINSUCNINAL
EPSS
1.97%
78.1th percentile
The Sieve engine in Dovecot before 2.3.15 allows Uncontrolled Resource Consumption, as demonstrated by a situation with a complex regular expression for the regex extension.

Affected

8 ranges
VendorProductVersion rangeFixed in
debiandovecot< dovecot 1:2.3.16+dfsg1-1 (bookworm)dovecot 1:2.3.16+dfsg1-1 (bookworm)
dovecotdovecot< 2.3.152.3.15
dovecotdovecot>= 0 < 1:2.3.16+dfsg1-11:2.3.16+dfsg1-1
dovecotdovecot>= 0 < 1:2.3.16+dfsg1-11:2.3.16+dfsg1-1
dovecotdovecot>= 0 < 1:2.3.16+dfsg1-11:2.3.16+dfsg1-1
fedoraprojectfedora
fedoraprojectfedora
msrccbl2_dovecot_2.3.20-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_msrc4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.