VYPR

Sasl

by Mellium

CVEs (1)

  • CVE-2022-48195CriDec 31, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Mellium mellium.im/sasl before 0.3.1. When performing SCRAM-based SASL authentication, if the remote end advertises support for channel binding, no random nonce is generated (instead, the nonce is empty). This causes authentication to fail in the best…