CVE Vulnerabilities

CVE-2014-5237

Published: Dec 01, 2014 | Modified: Dec 18, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Server-side request forgery (SSRF) vulnerability in the documentconverter component in Open-Xchange (OX) AppSuite before 7.4.2-rev10 and 7.6.x before 7.6.0-rev10 allows remote attackers to trigger requests to arbitrary servers and embed arbitrary images via a URL in an embedded image in a Text document, which is not properly handled by the image preview.

Affected Software

Name Vendor Start Version End Version
App_suite Open-xchange 7.4.2-rev6 (including) 7.4.2-rev6 (including)
App_suite Open-xchange 7.4.2-rev7 (including) 7.4.2-rev7 (including)
App_suite Open-xchange 7.4.2-rev8 (including) 7.4.2-rev8 (including)
App_suite Open-xchange 7.4.2-rev9 (including) 7.4.2-rev9 (including)
App_suite Open-xchange 7.6.0-rev6 (including) 7.6.0-rev6 (including)
App_suite Open-xchange 7.6.0-rev7 (including) 7.6.0-rev7 (including)
App_suite Open-xchange 7.6.0-rev8 (including) 7.6.0-rev8 (including)
App_suite Open-xchange 7.6.0-rev9 (including) 7.6.0-rev9 (including)

References