Sympa before 6.2.59b.2 allows remote attackers to obtain full SOAP API access by sending any arbitrary string (except one from an expired cookie) as the cookie value to authenticateAndRun.
| Software | From | Fixed in |
|---|---|---|
| sympa / sympa | 6.2.59-beta1 | 6.2.59-beta1.x |
| sympa / sympa | - | 6.2.58.x |
| fedoraproject / fedora | 32 | 32.x |
| fedoraproject / fedora | 33 | 33.x |
| debian / debian_linux | 9.0 | 9.0.x |
| debian / debian_linux | 10.0 | 10.0.x |