CVE-2023-26427: Low severity open-xchange app suite backend vulnerability
Default permissions for a properties file were too permissive. Local system users could read potentially sensitive information. We updated the default permissions for noreply.properties set during package installation. No publicly available exploits are known.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-26427?
CVE-2023-26427 is a vulnerability that occurs due to default permissions for a properties file being too permissive, allowing local system users to read potentially sensitive information.
What software is affected by CVE-2023-26427?
Open-xchange Appsuite Backend versions up to and including 7.10.6-revision_39 are affected by CVE-2023-26427.
How severe is CVE-2023-26427?
CVE-2023-26427 has a severity level of low (3.3) on the CVSS scale.
Are there any publicly available exploits for CVE-2023-26427?
No, there are no publicly available exploits known for CVE-2023-26427.
How can CVE-2023-26427 be fixed?
CVE-2023-26427 can be fixed by updating the default permissions for noreply.properties during package installation.