—
GO-2023-1630
Full authentication bypass if SASL authorization username is specified in github.com/foxcpp/maddy
Quick fix
GO-2023-1630 — github.com/foxcpp/maddy: upgrade to the fixed version with the command below.
go get github.com/foxcpp/maddy@v0.6.3Details
Full authentication bypass if SASL authorization username is specified in github.com/foxcpp/maddy
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/foxcpp/maddy
Introduced in:
0.2.0Fixed in: 0.6.3Fix
go get github.com/foxcpp/maddy@v0.6.3References
- https://github.com/foxcpp/maddy/security/advisories/GHSA-4g76-w3xw-2x6w[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2023-27582[ADVISORY]
- https://github.com/foxcpp/maddy/commit/55a91a37b71210f34f98f4d327c30308fe24399a[FIX]
- https://github.com/foxcpp/maddy/commit/9f58cb64b39cdc01928ec463bdb198c4c2313a9c[FIX]
- https://github.com/foxcpp/maddy/releases/tag/v0.6.3[WEB]