Vulnerability Description
Sympa before 6.2.59b.2 allows remote attackers to obtain full SOAP API access by sending any arbitrary string (except one from an expired cookie) as the cookie value to authenticateAndRun.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sympa | Sympa | <= 6.2.58 |
| Fedoraproject | Fedora | 32 |
| Debian | Debian Linux | 9.0 |
Related Weaknesses (CWE)
References
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=976020Mailing ListThird Party Advisory
- https://github.com/sympa-community/sympa/blob/6.2.59b.2/NEWS.mdRelease NotesThird Party Advisory
- https://github.com/sympa-community/sympa/issues/1041ExploitPatchThird Party Advisory
- https://github.com/sympa-community/sympa/pull/1044PatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/12/msg00026.htmlMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://www.debian.org/security/2020/dsa-4818Third Party Advisory
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=976020Mailing ListThird Party Advisory
- https://github.com/sympa-community/sympa/blob/6.2.59b.2/NEWS.mdRelease NotesThird Party Advisory
- https://github.com/sympa-community/sympa/issues/1041ExploitPatchThird Party Advisory
- https://github.com/sympa-community/sympa/pull/1044PatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/12/msg00026.htmlMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
FAQ
What is CVE-2020-29668?
CVE-2020-29668 is a vulnerability with a CVSS score of 3.7 (LOW). Sympa before 6.2.59b.2 allows remote attackers to obtain full SOAP API access by sending any arbitrary string (except one from an expired cookie) as the cookie value to authenticateAndRun.
How severe is CVE-2020-29668?
CVE-2020-29668 has been rated LOW with a CVSS base score of 3.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-29668?
Check the references section above for vendor advisories and patch information. Affected products include: Sympa Sympa, Fedoraproject Fedora, Debian Debian Linux.