CVE-2021-33054
published 2021-06-04CVE-2021-33054: SOGo 2.x before 2.4.1 and 3.x through 5.x before 5.1.1 does not validate the signatures of any SAML assertions it receives. Any actor with network access to…
PriorityP347high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.99%
59.0th percentile
SOGo 2.x before 2.4.1 and 3.x through 5.x before 5.1.1 does not validate the signatures of any SAML assertions it receives. Any actor with network access to the deployment could impersonate users when SAML is the authentication method. (Only versions after 2.0.5a are affected.)
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| alinto | sogo | >= 0 < 5.0.1-4+deb11u1 | 5.0.1-4+deb11u1 |
| alinto | sogo | >= 0 < 5.1.1-1 | 5.1.1-1 |
| alinto | sogo | >= 0 < 5.1.1-1 | 5.1.1-1 |
| alinto | sogo | >= 0 < 5.1.1-1 | 5.1.1-1 |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | sogo | < sogo 5.1.1-1 (bookworm) | sogo 5.1.1-1 (bookworm) |
| inverse | sogo | >= 2.0.6 < 2.4.1 | 2.4.1 |
| inverse | sogo | >= 3.0.0 < 5.1.1 | 5.1.1 |
| ubuntu | sogo | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_ubuntu6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5x58-gqg4-wfvq: SOGo 2
ghsa_unreviewed·2022-05-24
CVE-2021-33054 [HIGH] CWE-347 GHSA-5x58-gqg4-wfvq: SOGo 2
SOGo 2.x before 2.4.1 and 3.x through 5.x before 5.1.1 does not validate the signatures of any SAML assertions it receives. Any actor with network access to the deployment could impersonate users when SAML is the authentication method. (Only versions after 2.0.5a are affected.)
OSV
CVE-2021-33054: SOGo 2
osv·2021-06-04·CVSS 7.5
CVE-2021-33054 [HIGH] CVE-2021-33054: SOGo 2
SOGo 2.x before 2.4.1 and 3.x through 5.x before 5.1.1 does not validate the signatures of any SAML assertions it receives. Any actor with network access to the deployment could impersonate users when SAML is the authentication method. (Only versions after 2.0.5a are affected.)
Ubuntu
SOGo vulnerabilities
vendor_ubuntu·2026-07-05·CVSS 6.1
CVE-2026-8851 [MEDIUM] SOGo vulnerabilities
Title: SOGo vulnerabilities
Summary: Several security issues were fixed in SOGo.
It was discovered that SOGo did not properly sanitize categories used
for events, tasks, and contacts. A remote authenticated attacker could
possibly use this issue to perform cross-site scripting attacks. This
issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04
LTS, and Ubuntu 26.04 LTS. (CVE-2025-71276)
It was discovered that SOGo did not properly sanitize the hint query
parameter. A remote attacker could possibly use this issue to perform
cross-site scripting attacks. This issue only affected Ubuntu 26.04
LTS. (CVE-2026-3054)
It was discovered that SOGo did not renew the one-time password when a
user disabled and re-enabled it, and used a shorter length than
recommended. A remote attack
Debian
CVE-2021-33054: sogo - SOGo 2.x before 2.4.1 and 3.x through 5.x before 5.1.1 does not validate the sig...
vendor_debian·2021·CVSS 7.5
CVE-2021-33054 [HIGH] CVE-2021-33054: sogo - SOGo 2.x before 2.4.1 and 3.x through 5.x before 5.1.1 does not validate the sig...
SOGo 2.x before 2.4.1 and 3.x through 5.x before 5.1.1 does not validate the signatures of any SAML assertions it receives. Any actor with network access to the deployment could impersonate users when SAML is the authentication method. (Only versions after 2.0.5a are affected.)
Scope: local
bookworm: resolved (fixed in 5.1.1-1)
bullseye: resolved (fixed in 5.0.1-4+deb11u1)
forky: resolved (fixed in 5.1.1-1)
sid: resolved (fixed in 5.1.1-1)
trixie: resolved (fixed in 5.1.1-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://blogs.akamai.com/2021/06/sogo-and-packetfence-impacted-by-saml-implementation-vulnerabilities.htmlhttps://github.com/inverse-inc/sogo/blob/master/CHANGELOG.mdhttps://lists.debian.org/debian-lts-announce/2021/07/msg00007.htmlhttps://www.debian.org/security/2021/dsa-5029https://www.sogo.nu/news.htmlhttps://blogs.akamai.com/2021/06/sogo-and-packetfence-impacted-by-saml-implementation-vulnerabilities.htmlhttps://github.com/inverse-inc/sogo/blob/master/CHANGELOG.mdhttps://lists.debian.org/debian-lts-announce/2021/07/msg00007.htmlhttps://www.debian.org/security/2021/dsa-5029https://www.sogo.nu/news.html
2021-06-04
Published