This vulnerability affects maddy 0.5.1, 0.5.0 users using auth.shadow module and an extremely outdated system that still allows MD5 hashes in /etc/shadows.
Patch is available as part of the 0.5.2 release.
Ensure MD5 hashes are not present in /etc/shadow.
{
"nvd_published_at": null,
"github_reviewed_at": "2021-10-11T21:16:02Z",
"github_reviewed": true,
"severity": "LOW",
"cwe_ids": [
"CWE-261"
]
}