PT-2020-5770 · Sympa · Sympa

Racke

·

Published

2020-11-24

·

Updated

2022-04-26

·

CVE-2020-29668

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Sympa versions prior to 6.2.59b.2
Description: The issue is related to the authenticateAndRun function in the Sympa mailing list manager, which lacks proper cookie value validation. This allows a remote attacker to gain access to confidential data by sending any arbitrary string (except one from an expired cookie) as the cookie value to authenticateAndRun. This can provide full SOAP API access.
Recommendations: For versions prior to 6.2.59b.2, update to version 6.2.59b.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the authenticateAndRun function until a patch is available.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-01729
CVE-2020-29668
DLA-2499-1
DSA-4818-1

Affected Products

Sympa