Impact
A flaw in sogo_yhn’s SOGo configuration causes any HTTP request that includes the x-webobjects-remote-user header to be treated as originating from the specified user, bypassing password checks. The flaw lets an attacker pass arbitrary values for this header and gain access as any account, including privileged ones, without authentication.
Affected Systems
The vulnerability affects YunoHost‑Apps sogo_yhn installations that have not applied the fix introduced in version 5.8.0~ynh9. Any instance running a prior version is vulnerable.
Risk and Exploitability
With a CVSS score of 9.3 the issue is considered critical. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog; nonetheless the lack of authentication required for the bypass makes it trivially exploitable over the network. Attackers can trigger the capitalized bypass by simply including the x-webobjects-remote-user header in an HTTP request and are able to assume any user’s identity, including administrator-level access.
OpenCVE Enrichment