CVE-2023-27582Critical· 9.1▾ MidnightFull authentication bypass if SASL authorization username is specified
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 50.1 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
1.0%
maddy 0.2.0 - 0.6.2 allows a full authentication bypass if SASL authorization username is specified when using the PLAIN authentication mechanisms. Instead of validating the specified authorization username, it is accepted as is after checking the credentials for the authentication username.
maddy 0.6.3 includes the fix for the bug.
There is no way to fix the issue without upgrading.
github.com/foxcpp/maddy >= 0.2.0, < 0.6.3Upgrade to a patched release:
github.com/foxcpp/maddy 0.6.3