SOGo before 2.3.12 and 3.x before 3.1.1 does not restrict access to the UID and DTSTAMP attributes, which allows remote authenticated users to obtain sensitive information about appointments with the "View the Date & Time" restriction, as demonstrated by correlating UIDs and DTSTAMPs between all users.
{
"unresolved_ranges": [
{
"cpes": [
"cpe:2.3:a:inverse-inc:sogo:3.0.0:beta_1:*:*:*:*:*:*",
"cpe:2.3:a:inverse-inc:sogo:3.0.0:beta_2:*:*:*:*:*:*",
"cpe:2.3:a:inverse-inc:sogo:3.0.0:beta_3:*:*:*:*:*:*",
"cpe:2.3:a:inverse-inc:sogo:3.0.0:beta_4:*:*:*:*:*:*",
"cpe:2.3:a:inverse-inc:sogo:3.0.0:beta_5:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "3.0.0-beta_1"
},
{
"last_affected": "3.0.0-beta_1"
},
{
"introduced": "3.0.0-beta_2"
},
{
"last_affected": "3.0.0-beta_2"
},
{
"introduced": "3.0.0-beta_3"
},
{
"last_affected": "3.0.0-beta_3"
},
{
"introduced": "3.0.0-beta_4"
},
{
"last_affected": "3.0.0-beta_4"
},
{
"introduced": "3.0.0-beta_5"
},
{
"last_affected": "3.0.0-beta_5"
}
],
"source": "CPE_STRING",
"vendor_product": "inverse-inc:sogo"
}
]
}{
"cpe": [
"cpe:2.3:a:inverse-inc:sogo:*:*:*:*:*:*:*:*",
"cpe:2.3:a:inverse-inc:sogo:3.0.0:*:*:*:*:*:*:*",
"cpe:2.3:a:inverse-inc:sogo:3.0.1:*:*:*:*:*:*:*",
"cpe:2.3:a:inverse-inc:sogo:3.0.2:*:*:*:*:*:*:*",
"cpe:2.3:a:inverse-inc:sogo:3.1.0:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "2.3.11"
},
{
"introduced": "3.0.0"
},
{
"last_affected": "3.0.0"
},
{
"introduced": "3.0.1"
},
{
"last_affected": "3.0.1"
},
{
"introduced": "3.0.2"
},
{
"last_affected": "3.0.2"
},
{
"introduced": "3.1.0"
},
{
"last_affected": "3.1.0"
}
],
"source": [
"CPE_RANGE",
"CPE_STRING"
]
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-6190.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"272275947418062989887012245545970907197",
"237761867161411648712498103835426187177",
"231454080872523687104751719403681284838",
"193563563261601370690713969555675233477"
],
"threshold": 0.9
},
"id": "CVE-2016-6190-06b8778f",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/alinto/sogo/commit/717f45f640a2866b76a8984139391fae64339225",
"target": {
"file": "SoObjects/SOGo/SOGoUserSettings.h"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"272275947418062989887012245545970907197",
"237761867161411648712498103835426187177",
"231454080872523687104751719403681284838",
"193563563261601370690713969555675233477"
],
"threshold": 0.9
},
"id": "CVE-2016-6190-26f1ac38",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/alinto/sogo/commit/875a4aca3218340fd4d3141950c82c2ff45b343d",
"target": {
"file": "SoObjects/SOGo/SOGoUserSettings.h"
}
}
]
"2026-07-08T12:42:08Z"