Home
LOW: 2.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:NDefault status
unaffected
Any version before 5.12.5
affected
Description
SOGo before 5.12.5 does not renew the OTP if a user disables/enables it, and has a too short length (only 12 digits instead of the 20 recommended).
Problem types
CWE-308 Use of Single-factor Authentication
Product status
Any version before 5.12.5
References
github.com/...ommit/83d4c522f87cfde0ba543837d9b24c3479083ec2
github.com/Alinto/sogo/releases/tag/SOGo-5.12.5