CyberRota Analysis
AI-GeneratedThe vulnerability allows unauthenticated attackers to bypass HTTP Basic authentication in SOGo by exploiting the "SOGoTrustProxyAuthentication=YES" configuration, enabling them to log in as any existing user using any password. This critical security flaw poses a significant risk to user accounts and sensitive data. Organizations using affected versions should prioritize immediate updates to version 5.8.0~ynh9 to mitigate potential breaches.
Original NVD Description
sogo_yhn configures SOGo with a parameter "SOGoTrustProxyAuthentication=YES". This causes the password to be bypassed during HTTP Basic authentication. An unauthenticated attacker who provides the username of an existing user and any arbitrary password can successfully log in to that user's account. This issue was fixed in version 5.8.0~ynh9.