GHSA-4g76-w3xw-2x6w
CRITICALCVE-2023-27582maddy 0.2.0 - 0.6.2 allows a full authentication bypass if SASL authorization username is specified when using the PLAIN authentication mechanisms. Instead of validating the specified authorization username, it is accepted as is after checking the credentials for the authentication username.
- Affected
- >=0.2.0, <0.6.3
- Fixed in
- 0.6.3
- Published
- 2023-03-14
- Source
- github