Yunohost-Apps Sogo Yhn vulnerabilities
2 known vulnerabilities affecting yunohost-apps/sogo_yhn.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2
Vulnerabilities
Page 1 of 1
CVE-2026-74865P2CRITICALCVSS 9.2fixed in 5.8.0~ynh92026-09-30
CVE-2026-74865 [CRITICAL] CWE-639 CVE-2026-74865: sogo_yhn configures SOGo with a parameter "SOGoTrustProxyAuthentication=YES". This causes the passwo
sogo_yhn configures SOGo with a parameter "SOGoTrustProxyAuthentication=YES". This causes the password to be bypassed during HTTP Basic authentication. An unauthenticated attacker who provides the username of an existing user and any arbitrary password can successfully log in to that user's account.
This issue was fixed in version 5.8.0~ynh9.
nvd
CVE-2026-74864P2CRITICALCVSS 9.3fixed in 5.8.0~ynh92026-09-30
CVE-2026-74864 [CRITICAL] CWE-639 CVE-2026-74864: sogo_yhn configures SOGo with a parameter that forces the request with HTTP header "x-webobjects-rem
sogo_yhn configures SOGo with a parameter that forces the request with HTTP header "x-webobjects-remote-user" to be treated as sent by a verified user without performing password validation. Since Nginx does not strip this header, any client can supply it arbitrarily and gain access as any user, including a privileged user, without providing a pas
nvd