CVE-2021-28094: Weak Encryption
Published Jul 27, 2021
·Updated
OX Documents before 7.10.5-rev7 has Incorrect Access Control for converted documents because hash collisions can occur, due to use of CRC32.
Affected Software
8 affected components
Open-Xchange Open-xchange Documents<7.10.5
Open-Xchange Open-xchange Documents=7.10.5
Open-Xchange Open-xchange Documents=7.10.5-revision1
Open-Xchange Open-xchange Documents=7.10.5-revision2
Open-Xchange Open-xchange Documents=7.10.5-revision3
Open-Xchange Open-xchange Documents=7.10.5-revision4
Open-Xchange Open-xchange Documents=7.10.5-revision5
Open-Xchange Open-xchange Documents=7.10.5-revision6
Event History
Jul 27, 2021
CVE Published
via MITRE·05:08 AM
Data Sourced
via MITRE·05:08 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-28094?
CVE-2021-28094 has a medium severity rating due to improper access control for converted documents.
2
How do I fix CVE-2021-28094?
To fix CVE-2021-28094, upgrade to Open-Xchange Documents version 7.10.5-rev7 or later where the vulnerability is addressed.
3
What software is affected by CVE-2021-28094?
CVE-2021-28094 affects Open-Xchange Documents versions up to and including 7.10.5-rev6.
4
What type of vulnerability is CVE-2021-28094?
CVE-2021-28094 is classified as an access control vulnerability resulting from hash collisions.
5
Can CVE-2021-28094 be exploited remotely?
Yes, CVE-2021-28094 can potentially be exploited remotely due to improper access control mechanisms.