CVE-2021-33054

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
04/06/2021
Last modified:
29/03/2022

Description

SOGo 2.x before 2.4.1 and 3.x through 5.x before 5.1.1 does not validate the signatures of any SAML assertions it receives. Any actor with network access to the deployment could impersonate users when SAML is the authentication method. (Only versions after 2.0.5a are affected.)

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:inverse:sogo:*:*:*:*:*:*:*:* 2.0.6 (including) 2.4.1 (excluding)
cpe:2.3:a:inverse:sogo:*:*:*:*:*:*:*:* 3.0.0 (including) 5.1.1 (excluding)
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*