5.3

CVE-2022-37313

Exploit

OX App Suite through 7.10.6 allows SSRF because the anti-SSRF protection mechanism only checks the first DNS AA or AAAA record.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Open-xchangeOpen-xchange Appsuite Version < 7.10.5
Open-xchangeOpen-xchange Appsuite Version7.10.5 Update-
Open-xchangeOpen-xchange Appsuite Version7.10.5 Updatepatch_release_5961
Open-xchangeOpen-xchange Appsuite Version7.10.5 Updatepatch_release_5973
Open-xchangeOpen-xchange Appsuite Version7.10.5 Updatepatch_release_5976
Open-xchangeOpen-xchange Appsuite Version7.10.5 Updatepatch_release_5982
Open-xchangeOpen-xchange Appsuite Version7.10.5 Updatepatch_release_5989
Open-xchangeOpen-xchange Appsuite Version7.10.5 Updatepatch_release_5994
Open-xchangeOpen-xchange Appsuite Version7.10.5 Updatepatch_release_6000
Open-xchangeOpen-xchange Appsuite Version7.10.5 Updatepatch_release_6003
Open-xchangeOpen-xchange Appsuite Version7.10.5 Updatepatch_release_6008
Open-xchangeOpen-xchange Appsuite Version7.10.5 Updatepatch_release_6010
Open-xchangeOpen-xchange Appsuite Version7.10.5 Updatepatch_release_6016
Open-xchangeOpen-xchange Appsuite Version7.10.5 Updatepatch_release_6020
Open-xchangeOpen-xchange Appsuite Version7.10.5 Updatepatch_release_6026
Open-xchangeOpen-xchange Appsuite Version7.10.5 Updatepatch_release_6029
Open-xchangeOpen-xchange Appsuite Version7.10.5 Updatepatch_release_6034
Open-xchangeOpen-xchange Appsuite Version7.10.5 Updatepatch_release_6035
Open-xchangeOpen-xchange Appsuite Version7.10.5 Updatepatch_release_6038
Open-xchangeOpen-xchange Appsuite Version7.10.5 Updatepatch_release_6046
Open-xchangeOpen-xchange Appsuite Version7.10.5 Updatepatch_release_6051
Open-xchangeOpen-xchange Appsuite Version7.10.5 Updatepatch_release_6053
Open-xchangeOpen-xchange Appsuite Version7.10.5 Updatepatch_release_6060
Open-xchangeOpen-xchange Appsuite Version7.10.5 Updatepatch_release_6061
Open-xchangeOpen-xchange Appsuite Version7.10.5 Updatepatch_release_6066
Open-xchangeOpen-xchange Appsuite Version7.10.5 Updatepatch_release_6068
Open-xchangeOpen-xchange Appsuite Version7.10.5 Updatepatch_release_6072
Open-xchangeOpen-xchange Appsuite Version7.10.5 Updatepatch_release_6079
Open-xchangeOpen-xchange Appsuite Version7.10.5 Updatepatch_release_6084
Open-xchangeOpen-xchange Appsuite Version7.10.5 Updatepatch_release_6092
Open-xchangeOpen-xchange Appsuite Version7.10.5 Updatepatch_release_6101
Open-xchangeOpen-xchange Appsuite Version7.10.5 Updatepatch_release_6111
Open-xchangeOpen-xchange Appsuite Version7.10.5 Updatepatch_release_6120
Open-xchangeOpen-xchange Appsuite Version7.10.5 Updatepatch_release_6132
Open-xchangeOpen-xchange Appsuite Version7.10.5 Updatepatch_release_6137
Open-xchangeOpen-xchange Appsuite Version7.10.5 Updatepatch_release_6140
Open-xchangeOpen-xchange Appsuite Version7.10.5 Updatepatch_release_6149
Open-xchangeOpen-xchange Appsuite Version7.10.6 Update-
Open-xchangeOpen-xchange Appsuite Version7.10.6 Updatepatch_release_6069
Open-xchangeOpen-xchange Appsuite Version7.10.6 Updatepatch_release_6073
Open-xchangeOpen-xchange Appsuite Version7.10.6 Updatepatch_release_6080
Open-xchangeOpen-xchange Appsuite Version7.10.6 Updatepatch_release_6085
Open-xchangeOpen-xchange Appsuite Version7.10.6 Updatepatch_release_6093
Open-xchangeOpen-xchange Appsuite Version7.10.6 Updatepatch_release_6102
Open-xchangeOpen-xchange Appsuite Version7.10.6 Updatepatch_release_6112
Open-xchangeOpen-xchange Appsuite Version7.10.6 Updatepatch_release_6121
Open-xchangeOpen-xchange Appsuite Version7.10.6 Updatepatch_release_6133
Open-xchangeOpen-xchange Appsuite Version7.10.6 Updatepatch_release_6138
Open-xchangeOpen-xchange Appsuite Version7.10.6 Updatepatch_release_6141
Open-xchangeOpen-xchange Appsuite Version7.10.6 Updatepatch_release_6146
Open-xchangeOpen-xchange Appsuite Version7.10.6 Updatepatch_release_6147
Open-xchangeOpen-xchange Appsuite Version7.10.6 Updatepatch_release_6148
Open-xchangeOpen-xchange Appsuite Version7.10.6 Updatepatch_release_6150
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.46% 0.634
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
134c704f-9b21-4f2e-91b3-4a467353bcc0 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE-918 Server-Side Request Forgery (SSRF)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.