Full authentication bypass if SASL authorization username is specified
Description
Published by the National Vulnerability Database
Mar 13, 2023
Published to the GitHub Advisory Database
Mar 14, 2023
Reviewed
Mar 14, 2023
Last updated
Mar 14, 2023
Impact
maddy 0.2.0 - 0.6.2 allows a full authentication bypass if SASL authorization username is specified when using the PLAIN authentication mechanisms. Instead of validating the specified authorization username, it is accepted as is after checking the credentials for the authentication username.
Patches
maddy 0.6.3 includes the fix for the bug.
Workarounds
There is no way to fix the issue without upgrading.
References
References