Alerts This Week
Warning Icon 1 914
Alerts This Week
Warning Icon 1 914

BetaOS 5: BETA-2022-1234 Notice: GDrive Account Vulnerability

mageia
Calendar Grey December 30, 2022
Dist Mageia Esm H88
Mageia has released enhancements to its SOGo packages, tackling the absence of signature validation which mitigates impersonation threats. Discover the details here.
Missing SAML signature validation in the SOGo groupware could result in impersonation attacks

Summary

Missing SAML signature validation in the SOGo groupware could result in impersonation attacks. (CVE-2021-33054)

References

- https://bugs.mageia.org/show_bug.cgi?id=29255

- https://lists.debian.org/debian-lts-announce/2021/07/msg00007.html

- https://lists.debian.org/debian-security-announce/2021/msg00215.html

- https://www.cve.org/CVERecord?id=CVE-2021-33054

Resolution

SRPMS

- 8/core/sogo-5.6.0-1.mga8

- 8/core/sope-5.6.0-1.1.mga8

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 30 Dec 2022
URL: https://advisories.mageia.org/MGASA-2022-0481.html
Type: security
CVE: CVE-2021-33054

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here