CVE-2020-29668

LOW

Sympa < 6.2.59b.2 - Unauthenticated Improper Authentication via SOAP API Cookie Handling

Title source: llm
STIX 2.1

Description

Sympa before 6.2.59b.2 allows remote attackers to obtain full SOAP API access by sending any arbitrary string (except one from an expired cookie) as the cookie value to authenticateAndRun.

References (8)

Core 8
Core References
Exploit, Patch, Third Party Advisory x_refsource_misc
https://github.com/sympa-community/sympa/issues/1041
Patch, Third Party Advisory x_refsource_misc
https://github.com/sympa-community/sympa/pull/1044
Mailing List, Third Party Advisory x_refsource_misc
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=976020
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2020/12/msg00026.html
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2020/dsa-4818

Scores

CVSS v3 3.7
EPSS 0.0196
EPSS Percentile 77.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-287 CWE-565
Status published
Products (6)
debian/debian_linux 9.0
debian/debian_linux 10.0
fedoraproject/fedora 32
fedoraproject/fedora 33
sympa/sympa 6.2.59 beta1
sympa/sympa < 6.2.58
Published Dec 10, 2020
Tracked Since Feb 18, 2026