Aller au contenu

Fiche vulnérabilité

CVE-2022-48195 : faille critique mellium sasl (CVSS 9.8)

Description

An issue was discovered in Mellium mellium.im/sasl before 0.3.1. When performing SCRAM-based SASL authentication, if the remote end advertises support for channel binding, no random nonce is generated (instead, the nonce is empty). This causes authentication to fail in the best case, but (if paired with a remote end that does not validate the length of the nonce) could lead to insufficient randomness being used during authentication.

En bref

Sévérité
Critique (CVSS 9.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
31 déc. 2022
Dernière mise à jour
17 juin 2026

Produits concernés

  • mellium sasl

Références

Rechercher une autre vulnérabilité dans la base CVE