CVE-2021-28095: Weak Encryption
Published Jul 27, 2021
·Updated
OX Documents before 7.10.5-rev5 has Incorrect Access Control for documents that contain XML structures because hash collisions can occur, due to use of CRC32.
Affected Software
6 affected components
Open-Xchange Open-xchange Documents<7.10.5
Open-Xchange Open-xchange Documents=7.10.5
Open-Xchange Open-xchange Documents=7.10.5-revision1
Open-Xchange Open-xchange Documents=7.10.5-revision2
Open-Xchange Open-xchange Documents=7.10.5-revision3
Open-Xchange Open-xchange Documents=7.10.5-revision4
Event History
Jul 27, 2021
CVE Published
via MITRE·05:12 AM
Data Sourced
via MITRE·05:12 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-28095?
CVE-2021-28095 has a medium severity rating due to its potential for unauthorized access to sensitive documents.
2
How do I fix CVE-2021-28095?
To fix CVE-2021-28095, upgrade to OX Documents version 7.10.5-rev5 or later.
3
What type of vulnerability is CVE-2021-28095?
CVE-2021-28095 is classified as an access control vulnerability related to improper handling of XML data.
4
Which versions of Open-Xchange Documents are affected by CVE-2021-28095?
CVE-2021-28095 affects all versions of Open-Xchange Documents prior to 7.10.5-rev5.
5
What are the potential impacts of CVE-2021-28095?
The impact of CVE-2021-28095 includes possible exposure of confidential documents due to access control issues.