CVE-2025-30189 identifies a vulnerability in certain passdb/userdb drivers where, with caching enabled, user information is incorrectly cached, leading to subsequent logins being attributed to the wrong user; affected products are not specified. This high-severity vulnerability (CVSS 7.4) has a network attack vector and high attack complexity, potentially resulting in unauthorized access and significant impact on confidentiality and integrity. Despite its potential impact, there are currently no known public exploits, Metasploit modules, or Nuclei templates available, and it is not listed on the KEV catalog, indicating no active exploitation or significant community attention at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Open-Xchange GmbH | OX Dovecot Pro | >= 0, <= 2.4.0, >= 0, <= 3.1.0CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Using auth caching with oauth2 passdb, passwd passdb or userdb, or passwd userdb, causes the first lookup to be cached for all the lookups.
Oct 29, 2025Using auth caching with oauth2 passdb, passwd passdb or userdb, or passwd userdb, causes the first lookup to be cached for all the lookups.
Oct 29, 2025Using auth caching with oauth2 passdb, passwd passdb or userdb, or passwd userdb, causes the first lookup to be cached for all the lookups.
Oct 29, 2025Using auth caching with oauth2 passdb, passwd passdb or userdb, or passwd userdb, causes the first lookup to be cached for all the lookups.
Oct 29, 2025CVE-2025-30189: Using auth caching with oauth2 passdb, passwd passdb or userdb, or passwd userdb, causes the first lookup to be cached for all the lookups.
Oct 29, 2025Using auth caching with oauth2 passdb, passwd passdb or userdb, or passwd userdb, causes the first lookup to be cached for all the lookups.
Oct 29, 2025CVE-2025-30189: Using auth caching with oauth2 passdb, passwd passdb or userdb, or passwd userdb, causes the first lookup to be cached for all the lookups.
Oct 29, 2025