PatchSiren cyber security CVE debrief
CVE-2016-6189 Alinto CVE debrief
CVE-2016-6189 is an authenticated information disclosure issue in SOGo. An incomplete blacklist in the calendar feed handling could let a remote authenticated user read sensitive fields from ICS or XML calendar feeds. NVD rates the issue as medium severity (CVSS 4.3).
- Vendor
- Alinto
- Product
- Sogo
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-17
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-17
- Advisory updated
- 2026-05-13
Who should care
Administrators and security teams running SOGo deployments, especially instances that expose calendar feeds to authenticated users and may still be on versions earlier than 2.3.12 or 3.1.1.
Technical summary
The vulnerability affects SOGo before 2.3.12 and 3.x before 3.1.1. According to the NVD description, an incomplete blacklist allows remote authenticated users to obtain sensitive information by reading fields in ICS or XML calendar feeds. The published CVSS vector is AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N, indicating network reachability, low attack complexity, required low privileges, no user interaction, and confidentiality impact only.
Defensive priority
Medium. The issue is limited to authenticated users and confidentiality impact, but it can still expose sensitive calendar data in deployed SOGo services.
Recommended defensive actions
- Upgrade SOGo to 2.3.12 or later, or to 3.1.1 or later for 3.x deployments.
- Inventory all SOGo instances and confirm no affected version remains in production or test environments.
- Review which calendar feed fields are exposed to authenticated users and validate that sensitive data is not present in ICS or XML outputs.
- Restrict calendar feed access to the minimum necessary authenticated users and roles.
- Use vendor guidance and patches referenced in the public advisory trail to verify the fix is present in your build.
Evidence notes
The NVD record describes the flaw as an incomplete blacklist leading to sensitive information exposure through ICS or XML calendar feeds. The record lists affected version ranges as before 2.3.12 and 3.x before 3.1.1. Public references include a July 9, 2016 oss-security mailing list entry, two GitHub patch commits, and a SOGo bug tracker/vendor advisory page. No KEV listing is provided in the supplied corpus.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-6189 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-6189
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-6189 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-6189
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/inverse-inc/sogo/commit/717f45f640a2866b76a8984139391fae64339225
[email protected] - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/inverse-inc/sogo/commit/875a4aca3218340fd4d3141950c82c2ff45b343d
[email protected] - Patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.