PatchSiren

PatchSiren cyber security CVE debrief

CVE-2016-6189 Alinto CVE debrief

CVE-2016-6189 is an authenticated information disclosure issue in SOGo. An incomplete blacklist in the calendar feed handling could let a remote authenticated user read sensitive fields from ICS or XML calendar feeds. NVD rates the issue as medium severity (CVSS 4.3).

Vendor
Alinto
Product
Sogo
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2017-02-17
Original CVE updated
2026-05-13
Advisory published
2017-02-17
Advisory updated
2026-05-13

Who should care

Administrators and security teams running SOGo deployments, especially instances that expose calendar feeds to authenticated users and may still be on versions earlier than 2.3.12 or 3.1.1.

Technical summary

The vulnerability affects SOGo before 2.3.12 and 3.x before 3.1.1. According to the NVD description, an incomplete blacklist allows remote authenticated users to obtain sensitive information by reading fields in ICS or XML calendar feeds. The published CVSS vector is AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N, indicating network reachability, low attack complexity, required low privileges, no user interaction, and confidentiality impact only.

Defensive priority

Medium. The issue is limited to authenticated users and confidentiality impact, but it can still expose sensitive calendar data in deployed SOGo services.

Recommended defensive actions

  • Upgrade SOGo to 2.3.12 or later, or to 3.1.1 or later for 3.x deployments.
  • Inventory all SOGo instances and confirm no affected version remains in production or test environments.
  • Review which calendar feed fields are exposed to authenticated users and validate that sensitive data is not present in ICS or XML outputs.
  • Restrict calendar feed access to the minimum necessary authenticated users and roles.
  • Use vendor guidance and patches referenced in the public advisory trail to verify the fix is present in your build.

Evidence notes

The NVD record describes the flaw as an incomplete blacklist leading to sensitive information exposure through ICS or XML calendar feeds. The record lists affected version ranges as before 2.3.12 and 3.x before 3.1.1. Public references include a July 9, 2016 oss-security mailing list entry, two GitHub patch commits, and a SOGo bug tracker/vendor advisory page. No KEV listing is provided in the supplied corpus.

Sources and references

Verified primary and authoritative sources

  • CVE-2016-6189 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2016-6189

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2016-6189 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2016-6189

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.