CVE-2014-2392: Infoleak
The E-Mail autoconfiguration feature in Open-Xchange AppSuite before 7.2.2-rev20, 7.4.1 before 7.4.1-rev11, and 7.4.2 before 7.4.2-rev13 places a password in a GET request, which allows remote attackers to obtain sensitive information by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Open-Xchange AppSuite E-Mail autoconfigurationto a version that resolves this vulnerability.Fixed in 7.2.2-rev20 - Upgrade
Upgrade
Open-Xchange AppSuite E-Mail autoconfigurationto a version that resolves this vulnerability.Fixed in 7.4.1-rev11 - Upgrade
Upgrade
Open-Xchange AppSuite E-Mail autoconfigurationto a version that resolves this vulnerability.Fixed in 7.4.2-rev13 - Operational
If the exposed password may have been captured in web-server access logs, web-server Referer logs, or browser history, rotate/replace any potentially exposed credentials after upgrading.
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2392?
CVE-2014-2392 is classified as a moderate severity vulnerability due to the potential exposure of sensitive information.
How do I fix CVE-2014-2392?
To fix CVE-2014-2392, upgrade Open-Xchange AppSuite to versions 7.2.2-rev20, 7.4.1-rev11, or 7.4.2-rev13 or later.
What vulnerabilities does CVE-2014-2392 exploit?
CVE-2014-2392 exploits the E-Mail autoconfiguration feature by placing a password in a GET request.
Who is affected by CVE-2014-2392?
People using Open-Xchange AppSuite versions prior to 7.2.2-rev20, 7.4.1-rev11, and 7.4.2-rev13 are affected by CVE-2014-2392.
What information can be leaked due to CVE-2014-2392?
CVE-2014-2392 can lead to the leakage of sensitive information through web-server access and Referer logs.