9.6

CVE-2023-29050

The optional "LDAP contacts provider" could be abused by privileged users to inject LDAP filter strings that allow to access content outside of the intended hierarchy. Unauthorized users could break confidentiality of information in the directory and potentially cause high load on the directory server, leading to denial of service. Encoding has been added for user-provided fragments that are used when constructing the LDAP query. No publicly available exploits are known.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Open-xchange ≫ Ox App Suite Version < 7.10.6
Open-xchange ≫ Ox App Suite Version 7.10.6 Update -
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev01
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev02
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev03
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev04
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev05
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev06
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev07
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev08
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev09
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev10
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev11
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev12
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev13
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev14
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev15
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev16
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev17
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev18
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev19
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev20
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev21
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev22
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev23
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev24
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev25
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev26
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev27
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev28
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev29
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev30
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev31
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev32
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev33
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev34
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev35
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev36
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev37
Open-xchange ≫ Ox App Suite Version 7.10.6 Update rev50
Open-xchange ≫ Ox App Suite Version 8.16
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.67% 0.737
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.6 3.1 5.8
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H
security@open-xchange.com 7.6 2.3 4.7
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L
CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

CWE-90 Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')

The product constructs all or part of an LDAP query using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended LDAP query when it is sent to a downstream component.

http://packetstormsecurity.com/files/176421/OX-App-Suite-7.10.6-XSS-Command-Execution-LDAP-Injection.html
Third Party Advisory
VDB Entry
http://seclists.org/fulldisclosure/2024/Jan/3
Third Party Advisory
Mailing List
https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0005.json
Issue Tracking
https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6248_7.10.6_2023-09-19.pdf
Release Notes