Low severity3.7NVD Advisory· Published Dec 10, 2020· Updated Jun 17, 2026
CVE-2020-29668
CVE-2020-29668
Description
Sympa before 6.2.59b.2 allows remote attackers to obtain full SOAP API access by sending any arbitrary string (except one from an expired cookie) as the cookie value to authenticateAndRun.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
- Sympa/Sympadescription
Patches
Vulnerability mechanics
References
8- github.com/sympa-community/sympa/pull/1044nvdPatchThird Party Advisory
- github.com/sympa-community/sympa/issues/1041nvdExploitPatchThird Party Advisory
- bugs.debian.org/cgi-bin/bugreport.cginvdMailing ListThird Party Advisory
- github.com/sympa-community/sympa/blob/6.2.59b.2/NEWS.mdnvdRelease NotesThird Party Advisory
- lists.debian.org/debian-lts-announce/2020/12/msg00026.htmlnvdMailing ListThird Party Advisory
- www.debian.org/security/2020/dsa-4818nvdThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EFZWDEKQFW3EH665OECDWIWM2MI7T53Y/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JICIHAJKKCZXJNIICUDYXGZFQCN6J4U6/nvd
News mentions
0No linked articles in our index yet.