CVE-2023-29050: Critical severity open-xchange app suite backend vulnerability
The optional "LDAP contacts provider" could be abused by privileged users to inject LDAP filter strings that allow to access content outside of the intended hierarchy. Unauthorized users could break confidentiality of information in the directory and potentially cause high load on the directory server, leading to denial of service. Encoding has been added for user-provided fragments that are used when constructing the LDAP query. No publicly available exploits are known.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-29050?
CVE-2023-29050 is considered a high severity vulnerability due to its potential to allow unauthorized access to sensitive directory information.
Who is affected by CVE-2023-29050?
CVE-2023-29050 affects all versions of the Open-Xchange App Suite below 7.10.6 and specifically impacts configurations using the LDAP contacts provider.
How do I fix CVE-2023-29050?
To fix CVE-2023-29050, upgrade to Open-Xchange App Suite version 7.10.6 or later.
What are the potential consequences of CVE-2023-29050?
The potential consequences of CVE-2023-29050 include unauthorized access to confidential information and increased load on the directory server.
What actions should be taken regarding CVE-2023-29050?
Organizations should assess their use of the Open-Xchange App Suite and apply the necessary updates to mitigate risks associated with CVE-2023-29050.