Re: undocumented changed behavior of 2.4.3 (possible bug report)

Patrick Cernko via dovecot <[email protected]> Tue, 21 Apr 2026 13:59:22 +0200
Newsgroups gmane.mail.imap.dovecot
Organization Information Services & Technology, Joint Administration, Max Planck Institute for Informatics & Max Planck Institute for Software Systems
Message-ID <[email protected]>
Hi Aki,

thanks for the fast response!

On 2026-04-21 13:46:49, Aki Tuomi via dovecot wrote:
> For one, it's documented:
> 
> https://doc.dovecot.org/2.4.3/core/config/auth/databases/ldap.html#ldap_base
> 
> this is to avoid LDAP injection attack on authentication, CVE-2026-27860
> 
> But you're right, it should've been in the 2.4.x page.
> 

ah, I missed to check ldap_base and only checked the *_filter directives' docs. Maybe 
add that "| safe" note for the *_filter directives too?

Best regards,
-- 
Patrick Cernko <[email protected]> +49 681 9325 5815
Joint Scientific IT and Technical Service
Max-Planck-Institute für Informatik & Softwaresysteme

_______________________________________________
dovecot mailing list -- [email protected]
To unsubscribe send an email to [email protected]