CVE-2021-38378: Medium severity open-xchange app suite backend vulnerability
Published Nov 22, 2021
·Updated
OX App Suite 7.10.5 allows Information Exposure because a caching mechanism can caused a Modified By response to show a person's name.
Affected Software
1 affected component
Open-Xchange Ox App Suite<=7.10.5
Event History
Nov 22, 2021
CVE Published
via MITRE·08:54 AM
Data Sourced
via MITRE·08:54 AM
Description
Frequently Asked Questions
1
What is CVE-2021-38378?
CVE-2021-38378 is a vulnerability in OX App Suite 7.10.5 that allows information exposure due to a caching mechanism causing a Modified By response to show a person's name.
2
What is the severity of CVE-2021-38378?
The severity of CVE-2021-38378 is medium with a CVSS score of 4.3.
3
How does CVE-2021-38378 affect OX App Suite?
CVE-2021-38378 affects OX App Suite version 7.10.5.
4
How can the information exposure in OX App Suite be exploited?
An attacker can exploit the information exposure vulnerability in OX App Suite by leveraging the caching mechanism to view a person's name in the Modified By response.
5
Is there a fix for CVE-2021-38378?
At the moment, no official fix has been released for CVE-2021-38378. It is recommended to apply any security patches or updates provided by the vendor.