]> dgit.raspbian.org Git - dovecot.git/commitdiff
[PATCH 2/2] auth: Fix prefixing forward_fields without a value from client
authorMarkus Valentin <markus.valentin@open-xchange.com>
Thu, 23 Apr 2026 11:07:08 +0000 (13:07 +0200)
committerNoah Meyerhans <noahm@debian.org>
Wed, 16 Sep 2026 19:06:35 +0000 (15:06 -0400)
Bare tokens (without '=') were not prefixed, only key=value pairs were.
In practice this affected forward_fields, where a bare token such as
'nopassword' would land in extra_fields unprefixed instead of as
'forward_nopassword', allowing injection of internal auth control fields.

Gbp-Pq: Name 0002-auth-Fix-prefixing-forward_fields-without-a-value-fr.patch

src/auth/auth-fields.c

index 8b92836588302717d5d25a9b1bc50b113d4526ce..6e1ccbbcab8a94b375ad9b981d76451de6b4bf23 100644 (file)
@@ -125,7 +125,7 @@ static void auth_fields_import_prefixed_args(struct auth_fields *fields,
        for (; *args != NULL; args++) {
                value = strchr(*args, '=');
                if (value == NULL) {
-                       key = *args;
+                       key = *prefix != '\0' ? t_strconcat(prefix, *args, NULL) : *args;
                } else {
                        key = t_strdup_until(*args, value++);
                        if (*prefix != '\0')