sogo_yhn 在配置 SOGo 时,使用了一个参数强制将携带 HTTP 请求头 "x-webobjects-remote-user" 的请求视为来自已验证用户,而无需进行密码验证。由于 Nginx 不会移除该请求头,任何客户端都可以任意提供此头部,从而无需密码即可以任何用户(包括特权用户)的身份访问系统。 该问题已在版本 5.8.0~ynh9 中修复。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| YunoHost-Apps | sogo_yhn | < 5.8.0~ynh9 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| YunoHost-Apps | sogo_yhn | 0 ~ 5.8.0~ynh9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet