VDB
CVE-2021-32056
CVE-2021-32056
REJECTED
CVSS 4.300000190734863 MEDIUM
Cyrus IMAP before 3.2.7, and 3.3.x and 3.4.x before 3.4.1, allows remote authenticated users to bypass intended access restrictions on server annotations and consequently cause replication to stall.
EPSS 1.70% · 75.4th percentile
Risk Scores
CVSS 3.1
4.300000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
EPSS Score
1.70%
75.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:22.04:LTS | cyrus-imapd | 0, 3.2.6-2build1 |
| Ubuntu:24.04:LTS | cyrus-imapd | 0, 3.8.0-5, 3.8.1-1 |
Timeline
- May 10, 2021 CVE Published
- May 11, 2021 EPSS Score
- Jul 14, 2021 EPSS Score
- Sep 14, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Jan 15, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 20, 2022 EPSS Score
- Mar 18, 2022 EPSS Score
- May 19, 2022 EPSS Score
- Jul 21, 2022 EPSS Score
- Sep 21, 2022 EPSS Score
References
- https://ubuntu.com/security/CVE-2021-32056 third-party-advisory
- https://github.com/cyrusimap/cyrus-imapd/commit/621f9e41465b521399f691c241181300fab55995 third-party-advisory
- https://cyrus.topicbox.com/groups/announce/T126392718bc29d6b/cyrus-imap-3-2-7-released third-party-advisory
- https://www.cyrusimap.org/imap/download/release-notes/3.4/x/3.4.1.html third-party-advisory
- https://www.cyrusimap.org/imap/download/release-notes/3.2/x/3.2.7.html third-party-advisory
- https://cyrus.topicbox.com/groups/announce/T056901c106ecfce3/cyrus-imap-3-4-1-released third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2021-32056 third-party-advisory