Security advisory: Kopano Konnect & external SAML authority support

December 14, 2020

On monday the 14th of december the Mattermost team concluded their effort of a joined disclosure of issues found in a popular Golang XML parser also used in Kopano Konnect.

Users of Kopano Konnect who are using a SAML authority to sign into Konnect are recommended to update Konnect to version 0.33.11 or later.

The upstream advisory can be found at crewjam/saml – GHSA-4hq8-gmxx-h6w9

Affected products:

  • Kopano Konnect < 0.33.11

References:

Frequently asked questions (FAQ)

No. With the Kopano WebApp you can access your own mailbox and the content shared with you by other users in your organisation. To access mailboxes from different sources, you need a client such as Microsoft Outlook or Mozilla Thunderbird.
Native support in the WebApp is not currently planned. In addition to the use of clients, it may be possible to extend a browser on the respective end devices so that, for example, PGP can be used in the browser.
No. Kopano Cloud relies on ActiveSync for this purpose (for clients other than Outlook). ActiveSync is able to synchronise e-mails, calendars, contacts and tasks and has become widely accepted, especially by mobile devices.
No. Kopano Cloud relies on ActiveSync for this purpose (for clients other than Outlook). ActiveSync is able to synchronise e-mails, calendars, contacts and tasks and has become widely accepted, especially by mobile devices.
No. Kopano Cloud can be used with the native apps of the respective operating systems, or alternatively with third-party apps, provided they synchronise data via the ActiveSync or IMAP protocols.
Before a migration, data that is still needed should be transferred from public folders to separate/shared mailboxes
We recommend organising the move by using Outlook and PST files. In the case of large mailboxes, imapsync as a tool for e-mails can help to significantly reduce the amount of data in PST files.
Feedback of all kinds is always welcome. Please submit this via your supervising Kopano Cloud Partner.
Kopano Basic includes a minium of 10 users and Kopano Professional includes a minimum of 20 users in its base packages. For Kopano Enterprise it is 50 users. Our licenses for additional users increase by an increment of 5 users.
Please send us your question via the form below. We will contact you as soon as possible. If you want to reach out to us on specific / longer topics, please use our contact form!