PT-2022-17932 · Zarafa+3 · Zarafa Collaboration Platform+3
Published
2022-04-01
·
Updated
2024-07-04
·
CVE-2022-26562
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Kopano Core versions 11.0.2.51 and earlier
Zarafa Collaboration Platform versions 6.30 through 6.30.8
Description
The issue allows attackers to authenticate even if the user account or password is expired. This is due to a problem in the provider/libserver/ECKrbAuth.cpp file of Kopano Core and the provider/libserver/ECPamAuth.cpp file of Zarafa Collaboration Platform.
Recommendations
For Kopano Core versions 11.0.2.51 and earlier, update to a version later than 11.0.2.51 to resolve the issue.
For Zarafa Collaboration Platform versions 6.30 through 6.30.8, consider disabling the authentication mechanism in ECPamAuth.cpp until a patch is available.
As a temporary workaround, restrict access to the affected authentication module to minimize the risk of exploitation.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kopano Core
Linuxmint
Ubuntu
Zarafa Collaboration Platform