Appsuite
by Open-Xchange
CVEs (213)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-12644 | Med | 0.33 | 5.0 | 0.01 | Aug 31, 2020 | OX App Suite 7.10.3 and earlier allows SSRF, related to the mail account API and the /folder/list API. | ||
| CVE-2019-18846 | Med | 0.33 | 5.0 | 0.01 | Feb 21, 2020 | OX App Suite through 7.10.2 allows SSRF. | ||
| CVE-2020-15004 | Med | 0.31 | 4.8 | 0.03 | Oct 23, 2020 | OX App Suite through 7.10.3 allows stats/diagnostic?param= XSS. | ||
| CVE-2018-5756 | Med | 0.31 | 4.3 | 0.06 | Jun 16, 2018 | The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev44, and 7.8.4 before 7.8.4-rev22 does not properly check for folder-to-object association, which allows remote authenticated users to delete arbitrary tasks via… | ||
| CVE-2023-29046 | Med | 0.28 | 4.3 | 0.00 | Nov 2, 2023 | Connections to external data sources, like e-mail autoconfiguration, were not terminated in case they hit a timeout, instead those connections were logged. Some connections use user-controlled endpoints, which could be malicious and attempt to keep the connection open for an… | ||
| CVE-2023-26438 | Med | 0.28 | 4.3 | 0.01 | Aug 2, 2023 | External service lookups for a number of protocols were vulnerable to a time-of-check/time-of-use (TOCTOU) weakness, involving the JDK DNS cache. Attackers that were timing DNS cache expiry correctly were able to inject configuration that would bypass existing network… | ||
| CVE-2023-26434 | Med | 0.28 | 4.3 | 0.01 | Jun 20, 2023 | When adding an external mail account, processing of POP3 "capabilities" responses are not limited to plausible sizes. Attacker with access to a rogue POP3 service could trigger requests that lead to excessive resource usage and eventually service unavailability. We now limit… | ||
| CVE-2023-26433 | Med | 0.28 | 4.3 | 0.01 | Jun 20, 2023 | When adding an external mail account, processing of IMAP "capabilities" responses are not limited to plausible sizes. Attacker with access to a rogue IMAP service could trigger requests that lead to excessive resource usage and eventually service unavailability. We now limit… | ||
| CVE-2023-26432 | Med | 0.28 | 4.3 | 0.01 | Jun 20, 2023 | When adding an external mail account, processing of SMTP "capabilities" responses are not limited to plausible sizes. Attacker with access to a rogue SMTP service could trigger requests that lead to excessive resource usage and eventually service unavailability. We now limit… | ||
| CVE-2022-43698 | Med | 0.28 | 4.3 | 0.00 | Apr 15, 2023 | OX App Suite before 7.10.6-rev30 allows SSRF because changing a POP3 account disregards the deny-list. | ||
| CVE-2020-15003 | Med | 0.28 | 4.3 | 0.01 | Oct 23, 2020 | OX App Suite through 7.10.3 allows Information Exposure because a user can obtain the IP address and User-Agent string of a different user (via the session API during shared Drive access). | ||
| CVE-2020-12643 | Med | 0.28 | 4.3 | 0.01 | Aug 31, 2020 | OX App Suite 7.10.3 and earlier has Incorrect Access Control via an /api/subscriptions request for a snippet containing an email address. | ||
| CVE-2017-15029 | Med | 0.28 | 4.3 | 0.01 | May 23, 2019 | Open-Xchange GmbH OX App Suite 7.8.4 and earlier is affected by: SSRF. | ||
| CVE-2016-6852 | Med | 0.28 | 4.3 | 0.01 | Dec 15, 2016 | An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. Users can provide local file paths to the RSS reader; the response and error code give hints about whether the provided file exists or not. Attackers may discover specific system files or library versions on… | ||
| CVE-2016-4048 | Med | 0.28 | 4.3 | 0.01 | Dec 15, 2016 | An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev11. Custom messages can be shown at the login screen to notify external users about issues with sharing links. This mechanism can be abused to inject arbitrary text messages. Users may get tricked to follow… | ||
| CVE-2016-4047 | Med | 0.28 | 4.3 | 0.01 | Dec 15, 2016 | An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev8. References to external Open XML document type definitions (.dtd resources) can be placed within .docx and .xslx files. Those resources were requested when parsing certain parts of the generated document. As… | ||
| CVE-2023-26430 | Low | 0.23 | 3.5 | 0.01 | Aug 2, 2023 | Attackers with access to user accounts can inject arbitrary control characters to SIEVE mail-filter rules. This could be abused to access SIEVE extension that are not allowed by App Suite or to inject rules which would break per-user filter processing, requiring manual cleanup… | ||
| CVE-2023-26429 | Low | 0.23 | 3.5 | 0.01 | Jun 20, 2023 | Control characters were not removed when exporting user feedback content. This allowed attackers to include unexpected content via user feedback and potentially break the exported data structure. We now drop all control characters that are not whitespace character during the… | ||
| CVE-2016-4027 | Low | 0.23 | 3.5 | 0.01 | Dec 15, 2016 | An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev10. App Suite frontend offers to control whether a user wants to store cookies that exceed the session duration. This functionality is useful when logging in from clients with reduced privileges or shared… | ||
| CVE-2023-26427 | Low | 0.21 | 3.2 | 0.00 | Jun 20, 2023 | Default permissions for a properties file were too permissive. Local system users could read potentially sensitive information. We updated the default permissions for noreply.properties set during package installation. No publicly available exploits are known. |
- risk 0.33cvss 5.0epss 0.01
OX App Suite 7.10.3 and earlier allows SSRF, related to the mail account API and the /folder/list API.
- risk 0.33cvss 5.0epss 0.01
OX App Suite through 7.10.2 allows SSRF.
- risk 0.31cvss 4.8epss 0.03
OX App Suite through 7.10.3 allows stats/diagnostic?param= XSS.
- risk 0.31cvss 4.3epss 0.06
The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev44, and 7.8.4 before 7.8.4-rev22 does not properly check for folder-to-object association, which allows remote authenticated users to delete arbitrary tasks via…
- risk 0.28cvss 4.3epss 0.00
Connections to external data sources, like e-mail autoconfiguration, were not terminated in case they hit a timeout, instead those connections were logged. Some connections use user-controlled endpoints, which could be malicious and attempt to keep the connection open for an…
- risk 0.28cvss 4.3epss 0.01
External service lookups for a number of protocols were vulnerable to a time-of-check/time-of-use (TOCTOU) weakness, involving the JDK DNS cache. Attackers that were timing DNS cache expiry correctly were able to inject configuration that would bypass existing network…
- risk 0.28cvss 4.3epss 0.01
When adding an external mail account, processing of POP3 "capabilities" responses are not limited to plausible sizes. Attacker with access to a rogue POP3 service could trigger requests that lead to excessive resource usage and eventually service unavailability. We now limit…
- risk 0.28cvss 4.3epss 0.01
When adding an external mail account, processing of IMAP "capabilities" responses are not limited to plausible sizes. Attacker with access to a rogue IMAP service could trigger requests that lead to excessive resource usage and eventually service unavailability. We now limit…
- risk 0.28cvss 4.3epss 0.01
When adding an external mail account, processing of SMTP "capabilities" responses are not limited to plausible sizes. Attacker with access to a rogue SMTP service could trigger requests that lead to excessive resource usage and eventually service unavailability. We now limit…
- risk 0.28cvss 4.3epss 0.00
OX App Suite before 7.10.6-rev30 allows SSRF because changing a POP3 account disregards the deny-list.
- risk 0.28cvss 4.3epss 0.01
OX App Suite through 7.10.3 allows Information Exposure because a user can obtain the IP address and User-Agent string of a different user (via the session API during shared Drive access).
- risk 0.28cvss 4.3epss 0.01
OX App Suite 7.10.3 and earlier has Incorrect Access Control via an /api/subscriptions request for a snippet containing an email address.
- risk 0.28cvss 4.3epss 0.01
Open-Xchange GmbH OX App Suite 7.8.4 and earlier is affected by: SSRF.
- risk 0.28cvss 4.3epss 0.01
An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. Users can provide local file paths to the RSS reader; the response and error code give hints about whether the provided file exists or not. Attackers may discover specific system files or library versions on…
- risk 0.28cvss 4.3epss 0.01
An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev11. Custom messages can be shown at the login screen to notify external users about issues with sharing links. This mechanism can be abused to inject arbitrary text messages. Users may get tricked to follow…
- risk 0.28cvss 4.3epss 0.01
An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev8. References to external Open XML document type definitions (.dtd resources) can be placed within .docx and .xslx files. Those resources were requested when parsing certain parts of the generated document. As…
- risk 0.23cvss 3.5epss 0.01
Attackers with access to user accounts can inject arbitrary control characters to SIEVE mail-filter rules. This could be abused to access SIEVE extension that are not allowed by App Suite or to inject rules which would break per-user filter processing, requiring manual cleanup…
- risk 0.23cvss 3.5epss 0.01
Control characters were not removed when exporting user feedback content. This allowed attackers to include unexpected content via user feedback and potentially break the exported data structure. We now drop all control characters that are not whitespace character during the…
- risk 0.23cvss 3.5epss 0.01
An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev10. App Suite frontend offers to control whether a user wants to store cookies that exceed the session duration. This functionality is useful when logging in from clients with reduced privileges or shared…
- risk 0.21cvss 3.2epss 0.00
Default permissions for a properties file were too permissive. Local system users could read potentially sensitive information. We updated the default permissions for noreply.properties set during package installation. No publicly available exploits are known.
Page 9 of 11