Vulnerabilities > Sympa > Sympa > 6.2.43

DATE CVE VULNERABILITY TITLE RISK
2023-12-31 CVE-2021-46900 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Sympa
Sympa before 6.2.62 relies on a cookie parameter for certain security objectives, but does not ensure that this parameter exists and has an unpredictable value.
network
low complexity
sympa CWE-327
7.5
2020-12-10 CVE-2020-29668 Reliance on Cookies without Validation and Integrity Checking vulnerability in multiple products
Sympa before 6.2.59b.2 allows remote attackers to obtain full SOAP API access by sending any arbitrary string (except one from an expired cookie) as the cookie value to authenticateAndRun.
network
high complexity
sympa fedoraproject debian CWE-565
3.7
2020-10-07 CVE-2020-26880 Improper Privilege Management vulnerability in multiple products
Sympa through 6.2.57b.2 allows a local privilege escalation from the sympa user account to full root access by modifying the sympa.conf configuration file (which is owned by sympa) and parsing it through the setuid sympa_newaliases-wrapper executable.
local
low complexity
sympa fedoraproject debian CWE-269
7.8
2020-05-27 CVE-2020-10936 Improper Privilege Management vulnerability in multiple products
Sympa before 6.2.56 allows privilege escalation.
local
low complexity
sympa fedoraproject debian canonical CWE-269
7.8
2020-02-24 CVE-2020-9369 Resource Exhaustion vulnerability in multiple products
Sympa 6.2.38 through 6.2.52 allows remote attackers to cause a denial of service (disk consumption from temporary files, and a flood of notifications to listmasters) via a series of requests with malformed parameters.
network
low complexity
sympa fedoraproject debian CWE-400
7.5
2018-09-06 CVE-2018-1000671 Open Redirect vulnerability in multiple products
sympa version 6.2.16 and later contains a CWE-601: URL Redirection to Untrusted Site ('Open Redirect') vulnerability in The "referer" parameter of the wwsympa.fcgi login action.
network
sympa debian CWE-601
5.8