Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
SOGo 2.x before 2.4.1 and 3.x through 5.x before 5.1.1 does not validate the signatures of any SAML assertions it receives. Any actor with network access to the deployment could impersonate users when SAML is the authentication method. (Only versions after 2.0.5a are affected.)
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
SOGo 数据伪造问题漏洞
Vulnerability Description
SOGo是一个非常快速且可扩展的现代协作套件。它提供日历、地址簿管理和功能齐全的 Webmail 客户端以及资源共享和权限处理。 SOGo 存在安全漏洞,该漏洞源于当程序的SAML是身份验证方法时,任何对部署具有网络访问权限的参与者都可以模拟用户。以下产品及版本受到影响:SOGo 2.4.1之前版本、 5.1.1之前版本。
CVSS Information
N/A
Vulnerability Type
N/A