☢️ SOGo: critical vulnerability fixed in 5.8.0~ynh9

:uk: A critical security issue was discovered into the SOGo package. A fixed version was released in version 5.8.0~ynh9.

We recommend to upgrade SOGo as soon as possible on new version.

Due of some technical considerations, the SSO feature will be disabled until this package will migrate to SOGo 6 which is a full rewrite of the application.

Many thanks to Przemyslaw S. Knycz (@djrzulf on GitHub) for the discovery and analysis of the security issue.

We plan to leave one month as delay to update the instances before releasing the full details of the vulnerability.


:fr: Un problème de sécurité critique a été découvert dans le paquet SOGo. Une version avec le correctif a été publiée dans la version 5.8.0~ynh9.

Nous recommandons de mettre à jour SOGo dès que possible sur la nouvelle version.

Pour certaines raison techniques, la fonction SSO sera désactivée jusqu’à ce que ce paquet migre vers SOGo 6 qui est une réécriture complète de l’application.

Un grand merci à Przemyslaw S. Knycz (@djrzulf on GitHub) pour la découverte et l’analyse de la question de sécurité.

Nous prévoyons de laisser un mois comme délai pour mettre à jour les instances avant de publier tous les détails de la vulnérabilité.

The upgrade still didn’t succeed. Will you relese one for YNH 11?

Log:

This app requires YunoHost >= 12.1.38 but current installed version is 11.3.0.2

Hello,

I’m sorry but I don’t plan to provide any fix for Yunohost 11. But doing a backport would be doable. The security patch is this one.

Why are still on 11?

Thank you very much, with your help I could now hot-fix the /etc/sogo/sogo.conf until I can upgrade to YNH 12, much appreciated!

It’s still on 11, because it’s in a debian 11 container, and I’d need some time for potential troubleshooting to upgrade, or potentially redoing, that install.

Without security patches, maybe it would make sense to just call out for the offical end of support for 11?

You can take a snapshot and give it a try. But before that, ensure regen-conf doesn’t report issues. If it doesn’t go as expected then restore the snapshot

yunohost tools regen-conf --with-diff --dry-run

Shows only the shuffled resolv.dnsmasq.conf, but for sure there is more, e.g. the manual sogo.conf change is not listed.