2023-05a
mailcow/mailcow-dockerized2023-05aMay 30, 2023by DerLinkman
AI Summary
A critical security update fixing a Dovecot vulnerability (CVE-2023-34108) by removing a pass return in Lua auth and updating Dovecot to version 1.24.
Key Highlights
- Critical Dovecot password change vulnerability fix (CVE-2023-34108)
- Dovecot updated to version 1.24
- Maintainer changes for Dockerfiles
New Features
- Security patch for Dovecot
- Dovecot upgrade to 1.24
Full Release Notes
## What's Changed * Update dependency nextcloud/server to v26.0.2 by @renovate in https://github.com/mailcow/mailcow-dockerized/pull/5254 * [Dovecot] remove pass return in Dovecot lua auth by @FreddleSpl0it in https://github.com/mailcow/mailcow-dockerized/commit/67510adb9e0e354d0d16564a5156e3167bc28f8b * [Dovecot] Update to 1.24 by @DerLinkman in https://github.com/mailcow/mailcow-dockerized/commit/f82aba3e26a58c018283524098dc373ca6273172 * Changed maintainers to tinc (Dockerfiles) by @DerLinkman in https://github.com/mailcow/mailcow-dockerized/commit/70aab7568e7eea15d5d1777781bdcdfee06dbacd --- ## Information about 2023-05a This update contains a fix for a critical password change vulnerability in Dovecot (IMAP/POP3). We will release an official CVE in a few days (up to a week from now) with a detailed explanation and proof of concept for exploiting this desired security issue. We strongly recommend that you update to 2023-05a ASAP as this problem persists for a longer period of time (before 2020). **Please check the linked CVE regarding this issue: [CVE-2023-34108](https://nvd.nist.gov/vuln/detail/CVE-2023-34108)** **Full Changelog**: https://github.com/mailcow/mailcow-dockerized/compare/2023-05...2023-05a