{"id":"CVE-2022-24732","aliases":["GHSA-6cp7-g972-w9m9"],"url":"https://o3.security/vulnerability/CVE-2022-24732","summary":"Maddy Mail Server does not implement account expiry","details":"### Impact\n\nAny configuration on any maddy version <0.5.4 using auth.pam is affected.\n\nNo password expiry or account expiry checking is done when authenticating using PAM.\n\n### Patches\n\nPatch is available as part of the 0.5.4 release.\n\n### Workarounds\n\nIf /etc/shadow authentication is used, it is possible to replace auth.pam with auth.shadow which is not affected.\n\nIt is possible to blacklist expired accounts via existing filtering mechanisms (e.g. auth_map to invalid accounts in storage.imapsql).\n\n### References\n\n* https://github.com/foxcpp/maddy/blob/3412e59a2c92106e194fa69f2f1017c020037c9c/internal/auth/pam/pam.c\n* https://linux.die.net/man/3/pam_acct_mgmt\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in https://github.com/foxcpp/maddy\n* Email fox.cpp@disroot.org\n","published":"2022-03-09T19:40:08Z","modified":"2026-08-12T13:00:11.163220Z","cvss":{"score":6.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/foxcpp/maddy","fixedVersion":"0.5.4"}],"fix":{"url":"https://github.com/foxcpp/maddy/commit/7ee6a39c6a1939b376545f030a5efd6f90913583","label":"foxcpp/maddy@7ee6a39"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/24xxx/CVE-2022-24732.json"},{"type":"ADVISORY","url":"https://github.com/foxcpp/maddy/security/advisories/GHSA-6cp7-g972-w9m9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-24732"},{"type":"FIX","url":"https://github.com/foxcpp/maddy/commit/7ee6a39c6a1939b376545f030a5efd6f90913583"},{"type":"PACKAGE","url":"https://github.com/foxcpp/maddy"},{"type":"WEB","url":"https://github.com/foxcpp/maddy/releases/tag/v0.5.4"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T13:00:11.163220Z"}}