CVE-2020-24700: SSRF
Published Jan 12, 2021
·Updated
OX App Suite through 7.10.3 allows SSRF because GET requests are sent to arbitrary domain names with an initial autoconfig. substring.
Affected Software
1 affected component
Open-Xchange Open-Xchange AppSuite<=7.10.3
Event History
Jan 12, 2021
CVE Published
via MITRE·07:42 AM
Data Sourced
via MITRE·07:42 AM
Description
Frequently Asked Questions
1
What is CVE-2020-24700?
CVE-2020-24700 is a vulnerability in OX App Suite through 7.10.3 that allows SSRF attacks.
2
What is SSRF?
Server-Side Request Forgery (SSRF) is a vulnerability that allows an attacker to make requests from the vulnerable server to other internal or external resources.
3
How can an attacker exploit CVE-2020-24700?
An attacker can exploit CVE-2020-24700 by sending GET requests to arbitrary domain names with an initial 'autoconfig.' substring.
4
What is the severity of CVE-2020-24700?
The severity of CVE-2020-24700 is medium with a CVSS severity score of 5.4.
5
Is there a fix available for CVE-2020-24700?
Yes, updating OX App Suite to version 7.10.4 or later will fix the vulnerability.