Source: kopanocore X-Debbugs-CC: [email protected] Severity: important Tags: security
Hi, The following vulnerability was published for kopanocore. CVE-2022-26562[0]: | An issue in provider/libserver/ECKrbAuth.cpp of Kopano-Core v11.0.2.51 | contains an issue which allows attackers to authenticate even if the | user account or password is expired. The only refernece in the CVE database is https://stash.kopano.io/projects/KC/repos/kopanocore/browse/provider/libserver/ECKrbAuth.cpp#137 It's unclear whether this has actually been reported upstream. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2022-26562 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26562 Please adjust the affected versions in the BTS as needed.

