An issue in provider/libserver/ECKrbAuth.cpp of Kopano Core <= v11.0.2.51 contains an issue which allows attackers to authenticate even if the user account or password is expired. It also exists in the predecessor Zarafa Collaboration Platform (ZCP) in provider/libserver/ECPamAuth.cpp of Zarafa >= 6.30 (introduced between 6.30.0 RC1e and 6.30.8 final).
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade kopanocore | Mar 8, 2023 | Apr 1, 2022 |
| Ubuntu | — | Upgrade python-mapi (Ubuntu Pro)Upgrade kopano-libsUpgrade kopano-serverUpgrade kopano-spoolerUpgrade kopano-icalUpgrade kopano-utilsUpgrade php-mapi (Ubuntu Pro)Upgrade kopano-dagentUpgrade kopano-utils (Ubuntu Pro)Upgrade kopano-archiver (Ubuntu Pro)Upgrade kopano-server (Ubuntu Pro)Upgrade kopano-spooler (Ubuntu Pro)Upgrade kopano-archiverUpgrade kopano-dagent (Ubuntu Pro)Upgrade kopano-contactsUpgrade kopano-monitorUpgrade kopano-contacts (Ubuntu Pro)Upgrade kopano-gatewayUpgrade kopano-gateway (Ubuntu Pro)Upgrade php-mapiUpgrade kopano-libs (Ubuntu Pro)Upgrade kopano-monitor (Ubuntu Pro)Upgrade kopano-ical (Ubuntu Pro)Upgrade python3-mapi | Jul 9, 2024 | Apr 1, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub