First published: Thu Nov 02 2023(Updated: )
Documents operations could be manipulated to contain invalid data types, possibly script code. Script code could be injected to an operation that would be executed for users that are actively collaborating on the same document. Operation data exchanged between collaborating parties does now get escaped to avoid code execution. No publicly available exploits are known.
Credit: security@open-xchange.com
Affected Software | Affected Version | How to fix |
---|---|---|
<7.10.6 | ||
=7.10.6 | ||
=7.10.6-patch_release_6069 | ||
=7.10.6-patch_release_6073 | ||
=7.10.6-patch_release_6080 | ||
=7.10.6-patch_release_6085 | ||
=7.10.6-patch_release_6093 | ||
=7.10.6-patch_release_6102 | ||
=7.10.6-patch_release_6112 | ||
=7.10.6-patch_release_6121 | ||
=7.10.6-patch_release_6133 | ||
=7.10.6-patch_release_6138 | ||
=7.10.6-patch_release_6141 | ||
=7.10.6-patch_release_6146 | ||
=7.10.6-patch_release_6147 | ||
=7.10.6-patch_release_6148 | ||
=7.10.6-patch_release_6150 | ||
=7.10.6-patch_release_6156 | ||
=7.10.6-patch_release_6161 | ||
=7.10.6-patch_release_6166 | ||
=7.10.6-patch_release_6173 | ||
=7.10.6-patch_release_6176 | ||
=7.10.6-patch_release_6178 | ||
=7.10.6-patch_release_6189 | ||
=7.10.6-patch_release_6194 | ||
=7.10.6-patch_release_6199 | ||
=7.10.6-patch_release_6204 | ||
=7.10.6-patch_release_6205 | ||
=7.10.6-patch_release_6209 | ||
=7.10.6-patch_release_6210 | ||
=7.10.6-patch_release_6214 | ||
=7.10.6-patch_release_6215 | ||
=7.10.6-patch_release_6216 | ||
=7.10.6-patch_release_6218 | ||
=7.10.6-patch_release_6219 | ||
=7.10.6-patch_release_6220 | ||
=7.10.6-patch_release_6227 | ||
=7.10.6-patch_release_6230 | ||
=7.10.6-patch_release_6233 | ||
=7.10.6-patch_release_6235 | ||
=7.10.6-patch_release_6236 | ||
=7.10.6-patch_release_6239 | ||
=7.10.6-patch_release_6241 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-29044 is a vulnerability that allows manipulation of document operations to contain invalid data types, including possible script code injection.
CVE-2023-29044 has a severity level of medium, with a CVSS score of 5.4.
Open-xchange Open-xchange Appsuite versions up to and including 7.10.6 are affected by CVE-2023-29044.
To fix CVE-2023-29044, update Open-xchange Appsuite to version 7.10.6-patch_release_6243 or later.
You can find more information about CVE-2023-29044 in the Open-xchange Appsuite release notes for Patch Release 6243 and the associated security advisory.