CVE-2022-24732

Maddy Mail Server is an open source SMTP compatible email server. Versions of maddy prior to 0.5.4 do not implement password expiry or account expiry checking when authenticating using PAM. Users are advised to upgrade. Users unable to upgrade should manually remove expired accounts via existing filtering mechanisms.
Configurations

Configuration 1 (hide)

cpe:2.3:a:maddy_project:maddy:*:*:*:*:*:*:*:*

History

17 Mar 2022, 01:44

Type Values Removed Values Added
References (CONFIRM) https://github.com/foxcpp/maddy/security/advisories/GHSA-6cp7-g972-w9m9 - (CONFIRM) https://github.com/foxcpp/maddy/security/advisories/GHSA-6cp7-g972-w9m9 - Third Party Advisory
References (MISC) https://github.com/foxcpp/maddy/commit/7ee6a39c6a1939b376545f030a5efd6f90913583 - (MISC) https://github.com/foxcpp/maddy/commit/7ee6a39c6a1939b376545f030a5efd6f90913583 - Patch, Third Party Advisory
First Time Maddy Project
Maddy Project maddy
CVSS v2 : unknown
v3 : unknown
v2 : 6.5
v3 : 8.8
CPE cpe:2.3:a:maddy_project:maddy:*:*:*:*:*:*:*:*

09 Mar 2022, 20:22

Type Values Removed Values Added
New CVE

Information

Published : 2022-03-09 20:15

Updated : 2023-12-10 14:22


NVD link : CVE-2022-24732

Mitre link : CVE-2022-24732

CVE.ORG link : CVE-2022-24732


JSON object : View

Products Affected

maddy_project

  • maddy
CWE
CWE-324

Use of a Key Past its Expiration Date

CWE-613

Insufficient Session Expiration