There are 4 open security issues in bookworm.
2 important issues:
- CVE-2024-24510:
Cross Site Scripting vulnerability in Alinto SOGo before 5.10.0 allows a remote attacker to execute arbitrary code via the import function to the mail component.
- CVE-2025-53603:
In Alinto SOPE SOGo 2.0.2 through 5.12.2, sope-core/NGExtensions/NGHashMap.m allows a NULL pointer dereference and SOGo crash via a request in which a parameter in the query string is a duplicate of a parameter in the POST body.
2 issues left for the package maintainer to handle:
- CVE-2023-48104:
(needs triaging)
Alinto SOGo before 5.9.1 is vulnerable to HTML Injection.
- CVE-2024-34462:
(needs triaging)
Alinto SOGo through 5.10.0 allows XSS during attachment preview.
You can find information about how to handle these issues in the security team's documentation.