There are 4 open security issues in bookworm.
2 important issues:
- CVE-2024-24510:
Cross Site Scripting vulnerability in Alinto SOGo before 5.10.0 allows a remote attacker to execute arbitrary code via the import function to the mail component.
- CVE-2025-50340:
An Insecure Direct Object Reference (IDOR) vulnerability was discovered in SOGo Webmail thru 5.6.0, allowing an authenticated user to send emails on behalf of other users by manipulating a user-controlled identifier in the email-sending request. The server fails to verify whether the authenticated user is authorized to use the specified sender identity, resulting in unauthorized message delivery as another user. This can lead to impersonation, phishing, or unauthorized communication within the system.
2 issues left for the package maintainer to handle:
- CVE-2023-48104:
(needs triaging)
Alinto SOGo before 5.9.1 is vulnerable to HTML Injection.
- CVE-2024-34462:
(needs triaging)
Alinto SOGo through 5.10.0 allows XSS during attachment preview.
You can find information about how to handle these issues in the security team's documentation.