{"id":"GHSA-qh54-9vc5-m9fg","summary":"MD5 hash support in github.com/foxcpp/maddy","details":"### Impact\n\nThis vulnerability affects maddy 0.5.1, 0.5.0 users using auth.shadow module\nand an extremely outdated system that still allows MD5 hashes in \n/etc/shadows.\n\n### Patches\n\nPatch is available as part of the 0.5.2 release.\n\n### Workarounds\n\nEnsure MD5 hashes are not present in /etc/shadow.\n","aliases":["GO-2022-0378"],"modified":"2024-08-21T14:57:07.494061Z","published":"2021-10-12T16:06:30Z","database_specific":{"nvd_published_at":null,"severity":"LOW","github_reviewed":true,"cwe_ids":["CWE-261"],"github_reviewed_at":"2021-10-11T21:16:02Z"},"references":[{"type":"WEB","url":"https://github.com/foxcpp/maddy/security/advisories/GHSA-qh54-9vc5-m9fg"},{"type":"PACKAGE","url":"https://github.com/foxcpp/maddy"}],"affected":[{"package":{"name":"github.com/foxcpp/maddy","ecosystem":"Go","purl":"pkg:golang/github.com/foxcpp/maddy"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.5.0"},{"fixed":"0.5.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/10/GHSA-qh54-9vc5-m9fg/GHSA-qh54-9vc5-m9fg.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N"}]}