SOGo
Groupware server with shared calendars, address books and webmail
SOGo's release notes have become a vulnerability disclosure channel with a version number attached.
◆Recent moves
- 5d ago
Four more vulnerabilities patched; all prior versions affected
Another batch security release: a possible SQL injection on a specific request and several possible XSS injections, present since at least the May 12 nightly and affecting every previous version. CVE identifiers had not been issued at publication. The fourth such batch in five months, and the notes again urge immediate upgrade.
View source ↗ - 2mo ago
Patch undoes 5.12.8 regressions in preferences and mail display
Repairs four regressions introduced by the previous security release — preferences that would not save, event invitations rendering wrongly, and mail displayed incorrectly in search results. The recurring shape here: a fast security batch, then a patch cleaning up what it broke.
View source ↗ - 3mo ago
Two CVEs fixed for PostgreSQL user sources
Two major vulnerabilities fixed, this time scoped to a specific configuration rather than every deployment. Published after 5.12.8 despite the lower version number — a reminder that this feed's ordering does not follow its versioning.
View source ↗ - 3mo ago
Four vulnerabilities: XSS, SQL injection, OpenID impersonation
Two XSS paths through malicious mail, a SQL injection, and an OpenID impersonation issue, all affecting any previous version. The OpenID flaw is the most serious of the set — impersonation defeats authentication rather than degrading it.
View source ↗ - 4mo ago
TOTP silently disabled for new users, now fixed
Fixes a regression where newly added users could set up TOTP successfully, then find two-factor authentication silently disabled on their next login. A failure that presents as working until it matters — worse than an outright error, since neither the user nor the administrator sees a problem.
View source ↗ - 5mo ago
Injection fixes in hint queries, theme queries and categories
Community-reported injection fixes across hint queries, theme query script execution, and XSS in event, task and contact categories. The release that started the current run of security-driven versions, and the one that established the reporting channel the later batches came through.
View source ↗