GHSA-9gxx-32p7-ff7m
Dashboard / Vulnerabilities / GHSA-9gxx-32p7-ff7m
GHSA-9gxx-32p7-ff7m
Published: 18 Apr 2023Last Modified: 30 Sept 2024
Aliases:
Summary: Modoboa has Weak Password Requirements
Details: Modoboa 2.0.5 and prior allows users to set unsafe passwords, such as `1` or `HACK`. This issue is fixed in commit 130257c96a2392ada795785a91178e656e27015c and is part of version 2.1.0.
References: https://nvd.nist.gov/vuln/detail/CVE-2023-2160, https://github.com/modoboa/modoboa/commit/130257c96a2392ada795785a91178e656e27015c, https://github.com/modoboa/modoboa, https://github.com/pypa/advisory-database/tree/main/vulns/modoboa/PYSEC-2023-34.yaml, https://huntr.dev/bounties/54fb6d6a-6b39-45b6-b62a-930260ba484b
Affected packages
Package
Name: modoboa
Purl: pkg:pypi/modoboa
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -2.1.0
Affected versions
0.7.0
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
