CVE Vulnerabilities

CVE-2018-5756

Improper Privilege Management

Published: Jun 16, 2018 | Modified: Oct 03, 2019
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev44, and 7.8.4 before 7.8.4-rev22 does not properly check for folder-to-object association, which allows remote authenticated users to delete arbitrary tasks via the task id in a delete action to api/tasks.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Open-xchange_appsuite Open-xchange * 7.6.3 (including)
Open-xchange_appsuite Open-xchange 7.6.3-rev14 (including) 7.6.3-rev14 (including)
Open-xchange_appsuite Open-xchange 7.6.3-rev15 (including) 7.6.3-rev15 (including)
Open-xchange_appsuite Open-xchange 7.6.3-rev16 (including) 7.6.3-rev16 (including)
Open-xchange_appsuite Open-xchange 7.6.3-rev17 (including) 7.6.3-rev17 (including)
Open-xchange_appsuite Open-xchange 7.6.3-rev18 (including) 7.6.3-rev18 (including)
Open-xchange_appsuite Open-xchange 7.6.3-rev20 (including) 7.6.3-rev20 (including)
Open-xchange_appsuite Open-xchange 7.6.3-rev22 (including) 7.6.3-rev22 (including)
Open-xchange_appsuite Open-xchange 7.6.3-rev23 (including) 7.6.3-rev23 (including)
Open-xchange_appsuite Open-xchange 7.6.3-rev24 (including) 7.6.3-rev24 (including)
Open-xchange_appsuite Open-xchange 7.6.3-rev25 (including) 7.6.3-rev25 (including)
Open-xchange_appsuite Open-xchange 7.6.3-rev26 (including) 7.6.3-rev26 (including)
Open-xchange_appsuite Open-xchange 7.6.3-rev28 (including) 7.6.3-rev28 (including)
Open-xchange_appsuite Open-xchange 7.6.3-rev29 (including) 7.6.3-rev29 (including)
Open-xchange_appsuite Open-xchange 7.6.3-rev30 (including) 7.6.3-rev30 (including)
Open-xchange_appsuite Open-xchange 7.6.3-rev31 (including) 7.6.3-rev31 (including)
Open-xchange_appsuite Open-xchange 7.6.3-rev32 (including) 7.6.3-rev32 (including)
Open-xchange_appsuite Open-xchange 7.6.3-rev33 (including) 7.6.3-rev33 (including)
Open-xchange_appsuite Open-xchange 7.6.3-rev35 (including) 7.6.3-rev35 (including)
Open-xchange_appsuite Open-xchange 7.8.0 (including) 7.8.0 (including)
Open-xchange_appsuite Open-xchange 7.8.2 (including) 7.8.2 (including)
Open-xchange_appsuite Open-xchange 7.8.3 (including) 7.8.3 (including)
Open-xchange_appsuite Open-xchange 7.8.3-rev10 (including) 7.8.3-rev10 (including)
Open-xchange_appsuite Open-xchange 7.8.3-rev11 (including) 7.8.3-rev11 (including)
Open-xchange_appsuite Open-xchange 7.8.3-rev12 (including) 7.8.3-rev12 (including)
Open-xchange_appsuite Open-xchange 7.8.3-rev13 (including) 7.8.3-rev13 (including)
Open-xchange_appsuite Open-xchange 7.8.3-rev14 (including) 7.8.3-rev14 (including)
Open-xchange_appsuite Open-xchange 7.8.3-rev15 (including) 7.8.3-rev15 (including)
Open-xchange_appsuite Open-xchange 7.8.3-rev16 (including) 7.8.3-rev16 (including)
Open-xchange_appsuite Open-xchange 7.8.3-rev17 (including) 7.8.3-rev17 (including)
Open-xchange_appsuite Open-xchange 7.8.3-rev18 (including) 7.8.3-rev18 (including)
Open-xchange_appsuite Open-xchange 7.8.3-rev19 (including) 7.8.3-rev19 (including)
Open-xchange_appsuite Open-xchange 7.8.3-rev20 (including) 7.8.3-rev20 (including)
Open-xchange_appsuite Open-xchange 7.8.3-rev21 (including) 7.8.3-rev21 (including)
Open-xchange_appsuite Open-xchange 7.8.3-rev22 (including) 7.8.3-rev22 (including)
Open-xchange_appsuite Open-xchange 7.8.3-rev23 (including) 7.8.3-rev23 (including)
Open-xchange_appsuite Open-xchange 7.8.3-rev24 (including) 7.8.3-rev24 (including)
Open-xchange_appsuite Open-xchange 7.8.3-rev25 (including) 7.8.3-rev25 (including)
Open-xchange_appsuite Open-xchange 7.8.3-rev26 (including) 7.8.3-rev26 (including)
Open-xchange_appsuite Open-xchange 7.8.3-rev27 (including) 7.8.3-rev27 (including)
Open-xchange_appsuite Open-xchange 7.8.3-rev28 (including) 7.8.3-rev28 (including)
Open-xchange_appsuite Open-xchange 7.8.3-rev29 (including) 7.8.3-rev29 (including)
Open-xchange_appsuite Open-xchange 7.8.3-rev30 (including) 7.8.3-rev30 (including)
Open-xchange_appsuite Open-xchange 7.8.3-rev31 (including) 7.8.3-rev31 (including)
Open-xchange_appsuite Open-xchange 7.8.3-rev32 (including) 7.8.3-rev32 (including)
Open-xchange_appsuite Open-xchange 7.8.3-rev33 (including) 7.8.3-rev33 (including)
Open-xchange_appsuite Open-xchange 7.8.3-rev34 (including) 7.8.3-rev34 (including)
Open-xchange_appsuite Open-xchange 7.8.3-rev35 (including) 7.8.3-rev35 (including)
Open-xchange_appsuite Open-xchange 7.8.3-rev36 (including) 7.8.3-rev36 (including)
Open-xchange_appsuite Open-xchange 7.8.3-rev38 (including) 7.8.3-rev38 (including)
Open-xchange_appsuite Open-xchange 7.8.3-rev39 (including) 7.8.3-rev39 (including)
Open-xchange_appsuite Open-xchange 7.8.3-rev40 (including) 7.8.3-rev40 (including)
Open-xchange_appsuite Open-xchange 7.8.3-rev41 (including) 7.8.3-rev41 (including)
Open-xchange_appsuite Open-xchange 7.8.3-rev42 (including) 7.8.3-rev42 (including)
Open-xchange_appsuite Open-xchange 7.8.3-rev43 (including) 7.8.3-rev43 (including)
Open-xchange_appsuite Open-xchange 7.8.3-rev5 (including) 7.8.3-rev5 (including)
Open-xchange_appsuite Open-xchange 7.8.3-rev6 (including) 7.8.3-rev6 (including)
Open-xchange_appsuite Open-xchange 7.8.3-rev8 (including) 7.8.3-rev8 (including)
Open-xchange_appsuite Open-xchange 7.8.3-rev9 (including) 7.8.3-rev9 (including)
Open-xchange_appsuite Open-xchange 7.8.4 (including) 7.8.4 (including)
Open-xchange_appsuite Open-xchange 7.8.4-rev10 (including) 7.8.4-rev10 (including)
Open-xchange_appsuite Open-xchange 7.8.4-rev11 (including) 7.8.4-rev11 (including)
Open-xchange_appsuite Open-xchange 7.8.4-rev13 (including) 7.8.4-rev13 (including)
Open-xchange_appsuite Open-xchange 7.8.4-rev14 (including) 7.8.4-rev14 (including)
Open-xchange_appsuite Open-xchange 7.8.4-rev15 (including) 7.8.4-rev15 (including)
Open-xchange_appsuite Open-xchange 7.8.4-rev16 (including) 7.8.4-rev16 (including)
Open-xchange_appsuite Open-xchange 7.8.4-rev17 (including) 7.8.4-rev17 (including)
Open-xchange_appsuite Open-xchange 7.8.4-rev18 (including) 7.8.4-rev18 (including)
Open-xchange_appsuite Open-xchange 7.8.4-rev19 (including) 7.8.4-rev19 (including)
Open-xchange_appsuite Open-xchange 7.8.4-rev20 (including) 7.8.4-rev20 (including)
Open-xchange_appsuite Open-xchange 7.8.4-rev21 (including) 7.8.4-rev21 (including)
Open-xchange_appsuite Open-xchange 7.8.4-rev3 (including) 7.8.4-rev3 (including)
Open-xchange_appsuite Open-xchange 7.8.4-rev4 (including) 7.8.4-rev4 (including)
Open-xchange_appsuite Open-xchange 7.8.4-rev5 (including) 7.8.4-rev5 (including)
Open-xchange_appsuite Open-xchange 7.8.4-rev6 (including) 7.8.4-rev6 (including)
Open-xchange_appsuite Open-xchange 7.8.4-rev7 (including) 7.8.4-rev7 (including)
Open-xchange_appsuite Open-xchange 7.8.4-rev8 (including) 7.8.4-rev8 (including)
Open-xchange_appsuite Open-xchange 7.8.4-rev9 (including) 7.8.4-rev9 (including)

Potential Mitigations

References