CVE-2023-29051: High severity Open-Xchange Ox App Suite vulnerability
User-defined OXMF templates could be used to access a limited part of the internal OX App Suite Java API. The existing switch to disable the feature by default was not effective in this case. Unauthorized users could discover and modify application state, including objects related to other users and contexts. We now make sure that the switch to disable user-generated templates by default works as intended and will remove the feature in future generations of the product. No publicly available exploits are known.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-29051?
CVE-2023-29051 is considered to have a medium severity level due to the potential for unauthorized access to application state.
How do I fix CVE-2023-29051?
To fix CVE-2023-29051, update the OX App Suite to a version later than 7.10.6 that includes the security patch.
Who is affected by CVE-2023-29051?
CVE-2023-29051 affects users of the Open-Xchange OX App Suite version 7.10.6 and earlier versions.
What type of vulnerability is CVE-2023-29051?
CVE-2023-29051 is a security vulnerability that involves unauthorized access to Java API through user-defined templates.
What are the potential impacts of CVE-2023-29051?
The potential impacts of CVE-2023-29051 include unauthorized discovery and modification of application state, affecting user data and privacy.