Re: undocumented changed behavior of 2.4.3 (possible bug report)
Patrick Cernko via dovecot <[email protected]> Tue, 21 Apr 2026 13:59:22 +0200
| Newsgroups | gmane.mail.imap.dovecot |
|---|---|
| Organization | Information Services & Technology, Joint Administration, Max Planck Institute for Informatics & Max Planck Institute for Software Systems |
| Message-ID | <[email protected]> |
Hi Aki, thanks for the fast response! On 2026-04-21 13:46:49, Aki Tuomi via dovecot wrote: > For one, it's documented: > > https://doc.dovecot.org/2.4.3/core/config/auth/databases/ldap.html#ldap_base > > this is to avoid LDAP injection attack on authentication, CVE-2026-27860 > > But you're right, it should've been in the 2.4.x page. > ah, I missed to check ldap_base and only checked the *_filter directives' docs. Maybe add that "| safe" note for the *_filter directives too? Best regards, -- Patrick Cernko <[email protected]> +49 681 9325 5815 Joint Scientific IT and Technical Service Max-Planck-Institute für Informatik & Softwaresysteme _______________________________________________ dovecot mailing list -- [email protected] To unsubscribe send an email to [email protected]