CVE-2023-27582
Last modified
CVE-2023-27582 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. maddy is a composable, all-in-one mail server. Starting with version 0.2.0 and prior to version 0.6.3, maddy allows a full authentication bypass if SASL authorization username is specified when using the PLAIN authentication mechanisms. EPSS estimates a 1.02% chance of exploitation in the next 30 days.
Description
maddy is a composable, all-in-one mail server. Starting with version 0.2.0 and prior to version 0.6.3, maddy allows a full authentication bypass if SASL authorization username is specified when using the PLAIN authentication mechanisms. Instead of validating the specified username, it is accepted as is after checking the credentials for the authentication username. maddy 0.6.3 includes the fix for the bug. There are no known workarounds.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Maddy Project | Maddy | >= 0.2.0, < 0.6.3 |
References
- https://github.com/foxcpp/maddy/releases/tag/v0.6.3Release Notes
- https://github.com/foxcpp/maddy/security/advisories/GHSA-4g76-w3xw-2x6wPatch, Vendor Advisory
- https://github.com/foxcpp/maddy/releases/tag/v0.6.3Release Notes
- https://github.com/foxcpp/maddy/security/advisories/GHSA-4g76-w3xw-2x6wPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-27582?
How severe is CVE-2023-27582?
How do I fix CVE-2023-27582?
Are you affected by CVE-2023-27582?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
