Podatność CVE-2023-26442


Publikacja: 2023-08-02

Opis:
In case Cacheservice was configured to use a sproxyd object-storage backend, it would follow HTTP redirects issued by that backend. An attacker with access to a local or restricted network with the capability to intercept and replay HTTP requests to sproxyd (or who is in control of the sproxyd service) could perform a server-side request-forgery attack and make Cacheservice connect to unexpected resources. We have disabled the ability to follow HTTP redirects when connecting to sproxyd resources. No publicly available exploits are known.

W naszej bazie, znaleźliśmy następujące noty dla tego CVE:
Tytuł
Autor
Data
Med.
OX App Suite SSRF / SQL Injection / Cross Site Scripting
Mehmet Ince
03.08.2023

 Referencje:
https://documentation.open-xchange.com/security/advisories/csaf/oxas-adv-2023-0003.json
https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6230_7.10.6_2023-05-02.pdf

Copyright 2024, cxsecurity.com

 

Back to Top