CVE-2020-29668: Debian Linux
Low severity, CVSS 3.7. EPSS: 2% chance of exploitation in the next 30 days.
Sympa before 6.2.59b.2 allows remote attackers to obtain full SOAP API access by sending any arbitrary string (except one from an expired cookie) as the cookie value to authenticateAndRun.
Affected products
- Debian Debian Linux: version 9.0 only; version 10.0 only
- Fedoraproject Fedora: version 32 only; version 33 only
- Sympa Sympa: up to and including 6.2.58; version 6.2.59 only
Published 2020-12-10. Last modified 2026-06-17.