Description
Maddy Mail Server is an open source SMTP compatible email server. Versions of maddy prior to 0.5.4 do not implement password expiry or account expiry checking when authenticating using PAM. Users are advised to upgrade. Users unable to upgrade should manually remove expired accounts via existing filtering mechanisms.
Published: 2022-03-09
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-1342 Maddy Mail Server is an open source SMTP compatible email server. Versions of maddy prior to 0.5.4 do not implement password expiry or account expiry checking when authenticating using PAM. Users are advised to upgrade. Users unable to upgrade should manually remove expired accounts via existing filtering mechanisms.
Github GHSA Github GHSA GHSA-6cp7-g972-w9m9 Use of a Key Past its Expiration Date and Insufficient Session Expiration in Maddy Mail Server
History

Wed, 23 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Maddy Project Maddy
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-04-23T18:56:33.643Z

Reserved: 2022-02-10T00:00:00.000Z

Link: CVE-2022-24732

cve-icon Vulnrichment

Updated: 2024-08-03T04:20:49.847Z

cve-icon NVD

Status : Modified

Published: 2022-03-09T20:15:08.623

Modified: 2024-11-21T06:50:58.420

Link: CVE-2022-24732

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses