PT-2026-103127 · Nginx+1 · Nginx+1
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
sogo yhn versions prior to 5.8.0~ynh9
Description
The software is configured with a parameter that allows requests containing the
x-webobjects-remote-user HTTP header to be treated as coming from a verified user without password validation. Because Nginx does not strip this header, an attacker can provide it arbitrarily to gain unauthorized access to any account, including those with privileged permissions.Recommendations
Update to version 5.8.0~ynh9.
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nginx
Sogo Yhn