First published: Mon Jan 08 2024(Updated: )
User-defined OXMF templates could be used to access a limited part of the internal OX App Suite Java API. The existing switch to disable the feature by default was not effective in this case. Unauthorized users could discover and modify application state, including objects related to other users and contexts. We now make sure that the switch to disable user-generated templates by default works as intended and will remove the feature in future generations of the product. No publicly available exploits are known.
Credit: security@open-xchange.com
Affected Software | Affected Version | How to fix |
---|---|---|
open-xchange OX App Suite | <7.10.6 | |
open-xchange OX App Suite | =7.10.6 | |
open-xchange OX App Suite | =7.10.6-rev01 | |
open-xchange OX App Suite | =7.10.6-rev02 | |
open-xchange OX App Suite | =7.10.6-rev03 | |
open-xchange OX App Suite | =7.10.6-rev04 | |
open-xchange OX App Suite | =7.10.6-rev05 | |
open-xchange OX App Suite | =7.10.6-rev06 | |
open-xchange OX App Suite | =7.10.6-rev07 | |
open-xchange OX App Suite | =7.10.6-rev08 | |
open-xchange OX App Suite | =7.10.6-rev09 | |
open-xchange OX App Suite | =7.10.6-rev10 | |
open-xchange OX App Suite | =7.10.6-rev11 | |
open-xchange OX App Suite | =7.10.6-rev12 | |
open-xchange OX App Suite | =7.10.6-rev13 | |
open-xchange OX App Suite | =7.10.6-rev14 | |
open-xchange OX App Suite | =7.10.6-rev15 | |
open-xchange OX App Suite | =7.10.6-rev16 | |
open-xchange OX App Suite | =7.10.6-rev17 | |
open-xchange OX App Suite | =7.10.6-rev18 | |
open-xchange OX App Suite | =7.10.6-rev19 | |
open-xchange OX App Suite | =7.10.6-rev20 | |
open-xchange OX App Suite | =7.10.6-rev21 | |
open-xchange OX App Suite | =7.10.6-rev22 | |
open-xchange OX App Suite | =7.10.6-rev23 | |
open-xchange OX App Suite | =7.10.6-rev24 | |
open-xchange OX App Suite | =7.10.6-rev25 | |
open-xchange OX App Suite | =7.10.6-rev26 | |
open-xchange OX App Suite | =7.10.6-rev27 | |
open-xchange OX App Suite | =7.10.6-rev28 | |
open-xchange OX App Suite | =7.10.6-rev29 | |
open-xchange OX App Suite | =7.10.6-rev30 | |
open-xchange OX App Suite | =7.10.6-rev31 | |
open-xchange OX App Suite | =7.10.6-rev32 | |
open-xchange OX App Suite | =7.10.6-rev33 | |
open-xchange OX App Suite | =7.10.6-rev34 | |
open-xchange OX App Suite | =7.10.6-rev35 | |
open-xchange OX App Suite | =7.10.6-rev36 | |
open-xchange OX App Suite | =7.10.6-rev37 | |
open-xchange OX App Suite | =7.10.6-rev50 | |
open-xchange OX App Suite | =8.17 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-29051 is considered to have a medium severity level due to the potential for unauthorized access to application state.
To fix CVE-2023-29051, update the OX App Suite to a version later than 7.10.6 that includes the security patch.
CVE-2023-29051 affects users of the Open-Xchange OX App Suite version 7.10.6 and earlier versions.
CVE-2023-29051 is a security vulnerability that involves unauthorized access to Java API through user-defined templates.
The potential impacts of CVE-2023-29051 include unauthorized discovery and modification of application state, affecting user data and privacy.