CVE-2025-30189
When cache is enabled, some passdb/userdb drivers incorrectly cache all users with same cache key, causing wrong cached information to be used for these users. After cached login, all subsequent logins are for same user. Install fixed version or disable caching either globally or for the impacted passdb/userdb drivers. No publicly available exploits are known.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.4
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
- EPSS probability
- 0.54%
- CWE
- CWE-1250
- Published
- 2025-10-31
- Last modified
- 2026-03-27
Affected products
- Open-Xchange GmbH OX Dovecot Pro
Weakness type
Related vulnerabilities
- CVE-2026-14666 — PostgreSQL row security caching disregards role modifications
- CVE-2025-32899 — In KDE Connect before 1.33.0 on Android, a packet can be crafted that causes two paired devices to...
- CVE-2024-10976 — PostgreSQL row security below e.g. subqueries disregards user ID changes
- CVE-2023-22405 — Junos OS: QFX5k Series, EX46xx Series: MAC limiting feature stops working after PFE restart or device reboot
- CVE-2022-22234 — Junos OS: EX2300 and EX3400 Series: One of more SFPs might become unavailable when the system is very busy