{"id":"GHSA-qh54-9vc5-m9fg","aliases":["GO-2022-0378"],"url":"https://o3.security/vulnerability/GHSA-qh54-9vc5-m9fg","summary":"MD5 hash support in github.com/foxcpp/maddy","details":"### Impact\n\nThis vulnerability affects maddy 0.5.1, 0.5.0 users using auth.shadow module\nand an extremely outdated system that still allows MD5 hashes in \n/etc/shadows.\n\n### Patches\n\nPatch is available as part of the 0.5.2 release.\n\n### Workarounds\n\nEnsure MD5 hashes are not present in /etc/shadow.\n","published":"2021-10-12T16:06:30Z","modified":"2024-08-21T14:57:07.494061Z","cvss":{"score":3,"severity":"LOW","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/foxcpp/maddy","fixedVersion":"0.5.2"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/foxcpp/maddy/security/advisories/GHSA-qh54-9vc5-m9fg"},{"type":"PACKAGE","url":"https://github.com/foxcpp/maddy"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-08-21T14:57:07.494061Z"}}