CVE-2021-28093: Weak Encryption
Published Jul 27, 2021
·Updated
OX Documents before 7.10.5-rev5 has Incorrect Access Control of converted images because hash collisions can occur, due to use of Adler32.
Affected Software
6 affected components
Open-Xchange Open-xchange Documents<7.10.5
Open-Xchange Open-xchange Documents=7.10.5
Open-Xchange Open-xchange Documents=7.10.5-revision1
Open-Xchange Open-xchange Documents=7.10.5-revision2
Open-Xchange Open-xchange Documents=7.10.5-revision3
Open-Xchange Open-xchange Documents=7.10.5-revision4
Event History
Jul 27, 2021
CVE Published
via MITRE·05:09 AM
Data Sourced
via MITRE·05:09 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-28093?
CVE-2021-28093 is classified as a medium severity vulnerability that affects access control of converted images.
2
How do I fix CVE-2021-28093?
To remediate CVE-2021-28093, update Open-Xchange Documents to version 7.10.5-rev6 or later.
3
What versions are affected by CVE-2021-28093?
CVE-2021-28093 affects Open-Xchange Documents versions prior to 7.10.5-rev5.
4
What type of vulnerability is CVE-2021-28093?
CVE-2021-28093 is an improper access control vulnerability due to hash collisions.
5
Can CVE-2021-28093 lead to data exposure?
Yes, CVE-2021-28093 can potentially allow unauthorized users to access converted images.