Fedora Account System
Red Hat Associate
Red Hat Customer
Sympa before 6.2.59b.2 allows remote attackers to obtain full SOAP API access by sending any arbitrary string (except one from an expired cookie) as the cookie value to authenticateAndRun. Reference: https://github.com/sympa-community/sympa/issues/1041 Upstream patch: https://github.com/sympa-community/sympa/pull/1044
Created sympa tracking bugs for this issue: Affects: epel-7 [bug 1906578] Affects: fedora-all [bug 1906577]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.