CVE-2019-3814: If imap/pop3/managesieve/submission client has trusted certificate with missing username field (sslcertusername_field), under some configurations Dovecot mistakenly trusts the username provided via authentication instead of failing.
{ "section": "core" }
"https://advisories.mageia.org/MGASA-2019-0072.json"