CVE-2021-29157
published 2021-06-28CVE-2021-29157: Dovecot before 2.3.15 allows ../ Path Traversal. An attacker with access to the local filesystem can trick OAuth2 authentication into using an HS256 validation…
PriorityP426medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.47%
38.0th percentile
Dovecot before 2.3.15 allows ../ Path Traversal. An attacker with access to the local filesystem can trick OAuth2 authentication into using an HS256 validation key from an attacker-controlled location. This occurs during use of local JWT validation with the posix fs driver.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | dovecot | < dovecot 1:2.3.13+dfsg1-2 (bookworm) | dovecot 1:2.3.13+dfsg1-2 (bookworm) |
| dovecot | dovecot | >= 0 < 1:2.3.13+dfsg1-2 | 1:2.3.13+dfsg1-2 |
| dovecot | dovecot | >= 0 < 1:2.3.13+dfsg1-2 | 1:2.3.13+dfsg1-2 |
| dovecot | dovecot | >= 0 < 1:2.3.13+dfsg1-2 | 1:2.3.13+dfsg1-2 |
| dovecot | dovecot | >= 0 < 1:2.3.13+dfsg1-2 | 1:2.3.13+dfsg1-2 |
| dovecot | dovecot | >= 0 < 1:2.3.7.2-1ubuntu3.4 | 1:2.3.7.2-1ubuntu3.4 |
| dovecot | dovecot | >= 2.3.11 < 2.3.14.1 | 2.3.14.1 |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | cbl2_dovecot_2.3.20-1_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Dovecot vulnerabilities
vendor_ubuntu·2021-06-21·CVSS 7.5
CVE-2021-29157 [HIGH] Dovecot vulnerabilities
Title: Dovecot vulnerabilities
Summary: Several security issues were fixed in Dovecot.
Kirin discovered that Dovecot incorrectly escaped kid and azp fields in JWT
tokens. A local attacker could possibly use this issue to validate tokens
using arbitrary keys. This issue only affected Ubuntu 20.10 and Ubuntu
21.04. (CVE-2021-29157)
Fabian Ising and Damian Poddebniak discovered that Dovecot incorrectly
handled STARTTLS when using the SMTP submission service. A remote attacker
could possibly use this issue to inject plaintext commands before
STARTTLS negotiation. (CVE-2021-33515)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
dovecot: local attacker can login as any user and access their emails
vendor_redhat·2021-06-21·CVSS 7.5
CVE-2021-29157 [HIGH] CWE-20 dovecot: local attacker can login as any user and access their emails
dovecot: local attacker can login as any user and access their emails
Dovecot before 2.3.15 allows ../ Path Traversal. An attacker with access to the local filesystem can trick OAuth2 authentication into using an HS256 validation key from an attacker-controlled location. This occurs during use of local JWT validation with the posix fs driver.
A flaw was found in dovecot where it did not properly parse the `kid` and `azp` fields in JWT tokens. This flaw allows a local attacker to bypass dovecot's authentication, and access a user's emails. The highest threat from this vulnerability is to confidentiality and integrity.
Package: dovecot (Red Hat Enterprise Linux 6) - Out of support scope
Package: dovecot (Red Hat Enterprise Linux 7) - Not affected
Package: dovecot (Red Hat Enterprise Lin
Microsoft
Dovecot before 2.3.15 allows ../ Path Traversal. An attacker with access to the local filesystem can trick OAuth2 authentication into using an HS256 validation key from an attacker-controlled location
vendor_msrc·2021-06-08·CVSS 5.5
CVE-2021-29157 [HIGH] CWE-22 Dovecot before 2.3.15 allows ../ Path Traversal. An attacker with access to the local filesystem can trick OAuth2 authentication into using an HS256 validation key from an attacker-controlled location
Dovecot before 2.3.15 allows ../ Path Traversal. An attacker with access to the local filesystem can trick OAuth2 authentication into using an HS256 validation key from an attacker-controlled location. This occurs during use of local JWT validation with the posix fs driver.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more infor
Debian
CVE-2021-29157: dovecot - Dovecot before 2.3.15 allows ../ Path Traversal. An attacker with access to the ...
vendor_debian·2021·CVSS 7.5
CVE-2021-29157 [HIGH] CVE-2021-29157: dovecot - Dovecot before 2.3.15 allows ../ Path Traversal. An attacker with access to the ...
Dovecot before 2.3.15 allows ../ Path Traversal. An attacker with access to the local filesystem can trick OAuth2 authentication into using an HS256 validation key from an attacker-controlled location. This occurs during use of local JWT validation with the posix fs driver.
Scope: local
bookworm: resolved (fixed in 1:2.3.13+dfsg1-2)
bullseye: resolved (fixed in 1:2.3.13+dfsg1-2)
forky: resolved (fixed in 1:2.3.13+dfsg1-2)
sid: resolved (fixed in 1:2.3.13+dfsg1-2)
trixie: resolved (fixed in 1:2.3.13+dfsg1-2)
GHSA
GHSA-89g9-v7q6-px25: Dovecot before 2
ghsa_unreviewed·2022-05-24
CVE-2021-29157 [MEDIUM] CWE-22 GHSA-89g9-v7q6-px25: Dovecot before 2
Dovecot before 2.3.15 allows ../ Path Traversal. An attacker with access to the local filesystem can trick OAuth2 authentication into using an HS256 validation key from an attacker-controlled location. This occurs during use of local JWT validation with the posix fs driver.
OSV
CVE-2021-29157: Dovecot before 2
osv·2021-06-28·CVSS 5.5
CVE-2021-29157 [MEDIUM] CVE-2021-29157: Dovecot before 2
Dovecot before 2.3.15 allows ../ Path Traversal. An attacker with access to the local filesystem can trick OAuth2 authentication into using an HS256 validation key from an attacker-controlled location. This occurs during use of local JWT validation with the posix fs driver.
OSV
dovecot vulnerabilities
osv·2021-06-21·CVSS 5.5
CVE-2021-29157 [MEDIUM] dovecot vulnerabilities
dovecot vulnerabilities
Kirin discovered that Dovecot incorrectly escaped kid and azp fields in JWT
tokens. A local attacker could possibly use this issue to validate tokens
using arbitrary keys. This issue only affected Ubuntu 20.10 and Ubuntu
21.04. (CVE-2021-29157)
Fabian Ising and Damian Poddebniak discovered that Dovecot incorrectly
handled STARTTLS when using the SMTP submission service. A remote attacker
could possibly use this issue to inject plaintext commands before
STARTTLS negotiation. (CVE-2021-33515)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://dovecot.org/securityhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JB2VTJ3G2ILYWH5Y2FTY2PUHT2MD6VMI/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TK424DWFO2TKJYXZ2H3XL633TYJL4GQN/https://security.gentoo.org/glsa/202107-41https://www.openwall.com/lists/oss-security/2021/06/28/1https://dovecot.org/securityhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JB2VTJ3G2ILYWH5Y2FTY2PUHT2MD6VMI/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TK424DWFO2TKJYXZ2H3XL633TYJL4GQN/https://security.gentoo.org/glsa/202107-41https://www.openwall.com/lists/oss-security/2021/06/28/1
2021-06-28
Published