CVE-2022-24732

Maddy Mail Server is an open source SMTP compatible email server. Versions of maddy prior to 0.5.4 do not implement password expiry or account expiry checking when authenticating using PAM. Users are advised to upgrade. Users unable to upgrade should manually remove expired accounts via existing filtering mechanisms.
Configurations

Configuration 1 (hide)

cpe:2.3:a:maddy_project:maddy:*:*:*:*:*:*:*:*

History

21 Nov 2024, 06:50

Type Values Removed Values Added
References () https://github.com/foxcpp/maddy/commit/7ee6a39c6a1939b376545f030a5efd6f90913583 - Patch, Third Party Advisory () https://github.com/foxcpp/maddy/commit/7ee6a39c6a1939b376545f030a5efd6f90913583 - Patch, Third Party Advisory
References () https://github.com/foxcpp/maddy/security/advisories/GHSA-6cp7-g972-w9m9 - Third Party Advisory () https://github.com/foxcpp/maddy/security/advisories/GHSA-6cp7-g972-w9m9 - Third Party Advisory
CVSS v2 : 6.5
v3 : 8.8
v2 : 6.5
v3 : 6.3

Information

Published : 2022-03-09 20:15

Updated : 2024-11-21 06:50


NVD link : CVE-2022-24732

Mitre link : CVE-2022-24732

CVE.ORG link : CVE-2022-24732


JSON object : View

Products Affected

maddy_project

  • maddy
CWE
CWE-324

Use of a Key Past its Expiration Date

CWE-613

Insufficient Session Expiration