Sympa before 6.2.59b.2 allows remote attackers to obtain full SOAP API access by sending any arbitrary string (except one from an expired cookie) as the cookie value to authenticateAndRun.
{ "binaries": [ { "binary_name": "sympa", "binary_version": "6.1.24~dfsg-1ubuntu0.1~esm1" } ] }
{ "binaries": [ { "binary_name": "sympa", "binary_version": "6.2.24~dfsg-1ubuntu0.1~esm1" } ] }
{ "binaries": [ { "binary_name": "sympa", "binary_version": "6.2.40~dfsg-4ubuntu0.20.04.1~esm1" } ] }