Sympa before 6.2.59b.2 allows remote attackers to obtain full SOAP API access by sending any arbitrary string (except one from an expired cookie) as the cookie value to authenticateAndRun.
https://www.debian.org/security/2020/dsa-4818
https://lists.debian.org/debian-lts-announce/2020/12/msg00026.html
https://github.com/sympa-community/sympa/pull/1044
https://github.com/sympa-community/sympa/issues/1041
https://github.com/sympa-community/sympa/blob/6.2.59b.2/NEWS.md