Executive Summary

Informations
Name CVE-2023-29051 First vendor Publication 2024-01-08
Vendor Cve Last vendor Modification 2024-11-21

Security-Database Scoring CVSS v3

Cvss vector : CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Overall CVSS Score 8.1
Base Score 8.1 Environmental Score 8.1
impact SubScore 5.2 Temporal Score 8.1
Exploitabality Sub Score 2.8
 
Attack Vector Network Attack Complexity Low
Privileges Required Low User Interaction None
Scope Unchanged Confidentiality Impact High
Integrity Impact High Availability Impact None
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

User-defined OXMF templates could be used to access a limited part of the internal OX App Suite Java API. The existing switch to disable the feature by default was not effective in this case. Unauthorized users could discover and modify application state, including objects related to other users and contexts. We now make sure that the switch to disable user-generated templates by default works as intended and will remove the feature in future generations of the product. No publicly available exploits are known.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29051

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 42

Sources (Detail)

https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023...
https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Pat...
Source Url

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
Date Informations
2024-11-25 09:28:46
  • Multiple Updates
2024-01-22 17:27:39
  • Multiple Updates
2024-01-13 02:41:19
  • Multiple Updates
2024-01-13 02:35:24
  • Multiple Updates
2024-01-12 21:27:38
  • Multiple Updates
2024-01-12 13:27:29
  • Multiple Updates
2024-01-09 21:27:24
  • Multiple Updates
2024-01-09 05:27:23
  • Multiple Updates
2024-01-08 17:27:24
  • Multiple Updates
2024-01-08 13:27:26
  • First insertion