CVE-2023-24600: Medium severity open-xchange app suite backend vulnerability
Published May 29, 2023
·Updated
OX App Suite before backend 7.10.6-rev37 allows authenticated users to bypass access controls (for reading contacts) via a move to their own address book.
Affected Software
38 affected components
Open-Xchange Ox App Suite=7.10.6-rev01
Open-Xchange Ox App Suite=7.10.6-rev02
Open-Xchange Ox App Suite=7.10.6-rev03
Open-Xchange Ox App Suite=7.10.6-rev04
Open-Xchange Ox App Suite=7.10.6-rev05
Open-Xchange Ox App Suite=7.10.6-rev06
Open-Xchange Ox App Suite=7.10.6-rev07
Open-Xchange Ox App Suite=7.10.6-rev08
Open-Xchange Ox App Suite=7.10.6-rev09
Open-Xchange Ox App Suite=7.10.6-rev10
Open-Xchange Ox App Suite=7.10.6-rev11
Open-Xchange Ox App Suite=7.10.6-rev12
Open-Xchange Ox App Suite=7.10.6-rev13
Open-Xchange Ox App Suite=7.10.6-rev14
Open-Xchange Ox App Suite=7.10.6-rev15
Open-Xchange Ox App Suite=7.10.6-rev16
Open-Xchange Ox App Suite=7.10.6-rev17
Open-Xchange Ox App Suite=7.10.6-rev18
Open-Xchange Ox App Suite=7.10.6-rev19
Open-Xchange Ox App Suite=7.10.6-rev20
Open-Xchange Ox App Suite=7.10.6-rev21
Open-Xchange Ox App Suite=7.10.6-rev22
Open-Xchange Ox App Suite=7.10.6-rev23
Open-Xchange Ox App Suite=7.10.6-rev24
Open-Xchange Ox App Suite=7.10.6-rev25
Open-Xchange Ox App Suite=7.10.6-rev26
Open-Xchange Ox App Suite=7.10.6-rev27
Open-Xchange Ox App Suite=7.10.6-rev28
Open-Xchange Ox App Suite=7.10.6-rev29
Open-Xchange Ox App Suite=7.10.6-rev30
Open-Xchange Ox App Suite<7.10.6
Open-Xchange Ox App Suite=7.10.6
Open-Xchange Ox App Suite=7.10.6-rev36
Open-Xchange Ox App Suite=7.10.6-rev35
Open-Xchange Ox App Suite=7.10.6-rev34
Open-Xchange Ox App Suite=7.10.6-rev33
Open-Xchange Ox App Suite=7.10.6-rev32
Open-Xchange Ox App Suite=7.10.6-rev31
Event History
May 29, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-24600.
2
What is the severity level of CVE-2023-24600?
The severity level of CVE-2023-24600 is medium.
3
Which software versions are affected by CVE-2023-24600?
OX App Suite before backend 7.10.6-rev37 is affected by CVE-2023-24600.
4
How can authenticated users bypass access controls in CVE-2023-24600?
Authenticated users can bypass access controls (for reading contacts) in CVE-2023-24600 by moving contacts to their own address book.
5
Where can I find more information about CVE-2023-24600?
More information about CVE-2023-24600 can be found at the following references: [https://open-xchange.com](https://open-xchange.com), [http://seclists.org/fulldisclosure/2023/May/3](http://seclists.org/fulldisclosure/2023/May/3).