PyPi: Modoboa

CVE-2023-2160

Safety vulnerability ID: 55104

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at Apr 18, 2023 Updated at Mar 29, 2024
Scan your Python projects for vulnerabilities →

Advisory

Modoboa 2.1.0 includes a fix for a weak password requirement vulnerability.
https://github.com/modoboa/modoboa/pull/2949/commits/130257c96a2392ada795785a91178e656e27015c

Affected package

modoboa

Latest version: 2.2.4

Mail hosting made simple

Affected versions

Fixed versions

Vulnerability changelog

What's Changed
* added core language migration by Spitfireap in https://github.com/modoboa/modoboa/pull/2882
* Moved DMARC plugin back to core repo by tonioo in https://github.com/modoboa/modoboa/pull/2793
* added pdfcredential support for v2 by Spitfireap in https://github.com/modoboa/modoboa/pull/2791
* Added missing permissions on API endpoints by tonioo in https://github.com/modoboa/modoboa/pull/2888
* Fixed CSRF issues in edit operations. by tonioo in https://github.com/modoboa/modoboa/pull/2889
* Make sure to reset creation forms between 2 uses. by tonioo in https://github.com/modoboa/modoboa/pull/2887
* Added ability to disable inactive accounts by Spitfireap in https://github.com/modoboa/modoboa/pull/2885
* Bump django-otp from 1.1.4 to 1.1.6 by dependabot in https://github.com/modoboa/modoboa/pull/2910
* Translate 'frontend/locale/en/LC_MESSAGES/app.po' in 'fr' by transifex-integration in https://github.com/modoboa/modoboa/pull/2926
* Bump webpack from 5.74.0 to 5.76.1 in /frontend by dependabot in https://github.com/modoboa/modoboa/pull/2929
* Bump sideway/formula from 3.0.0 to 3.0.1 in /frontend by dependabot in https://github.com/modoboa/modoboa/pull/2930
* Added an alarm on dkim write error, reworked alarms by Spitfireap in https://github.com/modoboa/modoboa/pull/2884
* Added translation info to doc by Spitfireap in https://github.com/modoboa/modoboa/pull/2883
* Fixed security issue with password update. by tonioo in https://github.com/modoboa/modoboa/pull/2949
* Import imap-migration by Spitfireap in https://github.com/modoboa/modoboa/pull/2911
* Make sure to respect error field max length. by tonioo in https://github.com/modoboa/modoboa/pull/2956
* Display account quota usage in new UI by tonioo in https://github.com/modoboa/modoboa/pull/2958


**Full Changelog**: https://github.com/modoboa/modoboa/compare/2.0.5...2.1.0

Resources

Use this package?

Scan your Python project for dependency vulnerabilities in two minutes

Scan your application

Severity Details

CVSS Base Score

CRITICAL 9.8

CVSS v3 Details

CRITICAL 9.8
Attack Vector (AV)
NETWORK
Attack Complexity (AC)
LOW
Privileges Required (PR)
NONE
User Interaction (UI)
NONE
Scope (S)
UNCHANGED
Confidentiality Impact (C)
HIGH
Integrity Impact (I)
HIGH
Availability Availability (A)
HIGH