Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2020-29668
Description:Sympa before 6.2.59b.2 allows remote attackers to obtain full SOAP API access by sending any arbitrary string (except one from an expired cookie) as the cookie value to authenticateAndRun.
Test IDs: 1.3.6.1.4.1.25623.1.0.892499   1.3.6.1.4.1.25623.1.0.878793   1.3.6.1.4.1.25623.1.0.145041   1.3.6.1.4.1.25623.1.0.878794  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2020-29668
Debian Security Information: DSA-4818 (Google Search)
https://www.debian.org/security/2020/dsa-4818
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EFZWDEKQFW3EH665OECDWIWM2MI7T53Y/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JICIHAJKKCZXJNIICUDYXGZFQCN6J4U6/
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=976020
https://github.com/sympa-community/sympa/blob/6.2.59b.2/NEWS.md
https://github.com/sympa-community/sympa/issues/1041
https://github.com/sympa-community/sympa/pull/1044
https://lists.debian.org/debian-lts-announce/2020/12/msg00026.html




© 1998-2025 E-Soft Inc. All rights reserved.