An issue in provider/libserver/ECKrbAuth.cpp of Kopano-Core v11.0.2.51 contains an issue which allows attackers to authenticate even if the user account or password is expired.
References
Link | Resource |
---|---|
https://stash.kopano.io/projects/KC/repos/kopanocore/browse/provider/libserver/ECKrbAuth.cpp#137 | Exploit Vendor Advisory |
https://kopano.com/ | Vendor Advisory |
https://lists.debian.org/debian-lts-announce/2023/03/msg00006.html |
Configurations
Information
Published : 2022-04-01 13:15
Updated : 2023-03-06 09:15
NVD link : CVE-2022-26562
Mitre link : CVE-2022-26562
JSON object : View
CWE
CWE-287
Improper Authentication
Products Affected
kopano
- groupware_core