PT-2023-21225 · Maddy · Maddy
Foxcpp
·
Publicado
2023-03-13
·
Atualizado
2024-08-20
·
CVE-2023-27582
CVSS v3.1
9.1
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
maddy versions 0.2.0 through 0.6.2
Description
The issue allows for a full authentication bypass if a SASL authorization username is specified when using the PLAIN authentication mechanisms. Instead of validating the specified username, it is accepted as is after checking the credentials for the authentication username.
Recommendations
For versions 0.2.0 through 0.6.2, upgrade to version 0.6.3 to resolve the issue.
As a temporary workaround, consider disabling the use of the PLAIN authentication mechanisms until a patch is available.
Restrict access to the SASL authorization username to minimize the risk of exploitation.
Exploit
Correção
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Maddy