CVE-2022-48195

CRITICAL

mellium/sasl < 0.3.1 - Improper Authentication via Empty Nonce in SCRAM

Title source: llm
STIX 2.1

Description

An issue was discovered in Mellium mellium.im/sasl before 0.3.1. When performing SCRAM-based SASL authentication, if the remote end advertises support for channel binding, no random nonce is generated (instead, the nonce is empty). This causes authentication to fail in the best case, but (if paired with a remote end that does not validate the length of the nonce) could lead to insufficient randomness being used during authentication.

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.0088
EPSS Percentile 54.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-287
Status published
Products (2)
mellium/sasl 0.3.0
mellium.im/sasl 0 - 0.3.1Go
Published Dec 31, 2022
Tracked Since Feb 18, 2026