CVE-2025-30189CWE-1250

When cache is enabled, some passdb/userdb drivers incorrectly cache all users with same cache key, causing wrong cached information to be used for these users

High · published October 31, 2025

CVSS v3.1
7.4
EPSS
1%
Percentile
43.4
In the wild
Unconfirmed
What it is

🚨 A caching hiccup is causing a real identity crisis! When cache is enabled, all users end up sharing the same credentials—imagine every guest at a hotel sharing one room key! 🔥 Think of a high-tech hotel where every guest receives the same room key because of a glitch in the system. Instead of keeping their own unique room, guests accidentally find themselves barging into each other’s spaces, leading to quite the mix-up! This can lead to some absolutely devastating consequences—users could unknowingly log in as someone else, accessing their sensitive information and settings. Imagine the chaos if Bob suddenly finds himself in Alice's account, changing her preferences or even worse, accessing her private messages!

Put simply

Think of a high-tech hotel where every guest receives the same room key because of a glitch in the system. Instead of keeping their own unique room, guests accidentally find themselves barging into each other’s spaces, leading to quite the mix-up! This vulnerability exists due to some passdb/userdb drivers incorrectly caching all users with the same key, meaning that once one user logs in and their information is cached, all subsequent logins will use that same cached data for anyone else attempting to authenticate.

What to do

This can lead to some absolutely devastating consequences—users could unknowingly log in as someone else, accessing their sensitive information and settings. Imagine the chaos if Bob suddenly finds himself in Alice's account, changing her preferences or even worse, accessing her private messages! To protect your system, either install the fixed version of the software or disable caching globally or for the impacted passdb/userdb drivers. It's crucial to act quickly to prevent any potential user mix-ups! You've got this! Follow these steps, and you'll be securing those user accounts in no time. 🛡️

The record
Technical detail
CVSS v3.1
7.4 · HIGH
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS v4.0
Not supplied
EPSS
0.00540 · 43.4th percentile
Weakness
CWE-1250 · Improper Preservation of Consistency Between Independent Representations of Shared State
Published
2025-10-31T09:02Z
EPSS history
Timeline
  • 31 OCT 09:02Z
    When cache is enabled, some passdb/userdb drivers incorrectly cache all users with same cache key, causing wrong cached information to be used for these users
    cvelistv5