2023-05a

mailcow/mailcow-dockerized2023-05aMay 30, 2023by DerLinkman

AI Summary

A critical security update fixing a Dovecot vulnerability (CVE-2023-34108) by removing a pass return in Lua auth and updating Dovecot to version 1.24.

Key Highlights

  • Critical Dovecot password change vulnerability fix (CVE-2023-34108)
  • Dovecot updated to version 1.24
  • Maintainer changes for Dockerfiles

New Features

  • Security patch for Dovecot
  • Dovecot upgrade to 1.24

Full Release Notes

## What's Changed
* Update dependency nextcloud/server to v26.0.2 by @renovate in https://github.com/mailcow/mailcow-dockerized/pull/5254
* [Dovecot] remove pass return in Dovecot lua auth by @FreddleSpl0it in https://github.com/mailcow/mailcow-dockerized/commit/67510adb9e0e354d0d16564a5156e3167bc28f8b
* [Dovecot] Update to 1.24 by @DerLinkman in https://github.com/mailcow/mailcow-dockerized/commit/f82aba3e26a58c018283524098dc373ca6273172
* Changed maintainers to tinc (Dockerfiles) by @DerLinkman in https://github.com/mailcow/mailcow-dockerized/commit/70aab7568e7eea15d5d1777781bdcdfee06dbacd

---
## Information about 2023-05a
This update contains a fix for a critical password change vulnerability in Dovecot (IMAP/POP3). We will release an official CVE in a few days (up to a week from now) with a detailed explanation and proof of concept for exploiting this desired security issue.

We strongly recommend that you update to 2023-05a ASAP as this problem persists for a longer period of time (before 2020).

**Please check the linked CVE regarding this issue: [CVE-2023-34108](https://nvd.nist.gov/vuln/detail/CVE-2023-34108)**

**Full Changelog**: https://github.com/mailcow/mailcow-dockerized/compare/2023-05...2023-05a