9.8
CVSSv3

CVE-2022-48195

Published: 31/12/2022 Updated: 09/01/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

An issue exists in Mellium mellium.im/sasl prior to 0.3.1. When performing SCRAM-based SASL authentication, if the remote end advertises support for channel binding, no random nonce is generated (instead, the nonce is empty). This causes authentication to fail in the best case, but (if paired with a remote end that does not validate the length of the nonce) could lead to insufficient randomness being used during authentication.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mellium sasl 0.3.0

Vendor Advisories

DescriptionThe MITRE CVE dictionary describes this issue as: An issue was discovered in Mellium melliumim/sasl before 031 When performing SCRAM-based SASL authentication, if the remote end advertises support for channel binding, no random nonce is generated (instead, the nonce is empty) This causes authentication to fail in the best case, but ...