CVE Vulnerabilities

CVE-2023-24600

Published: May 29, 2023 | Modified: Jun 01, 2023
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

OX App Suite before backend 7.10.6-rev37 allows authenticated users to bypass access controls (for reading contacts) via a move to their own address book.

Affected Software

Name Vendor Start Version End Version
Ox_app_suite Open-xchange * 7.10.6 (excluding)
Ox_app_suite Open-xchange 7.10.6 (including) 7.10.6 (including)
Ox_app_suite Open-xchange 7.10.6-rev01 (including) 7.10.6-rev01 (including)
Ox_app_suite Open-xchange 7.10.6-rev02 (including) 7.10.6-rev02 (including)
Ox_app_suite Open-xchange 7.10.6-rev03 (including) 7.10.6-rev03 (including)
Ox_app_suite Open-xchange 7.10.6-rev04 (including) 7.10.6-rev04 (including)
Ox_app_suite Open-xchange 7.10.6-rev05 (including) 7.10.6-rev05 (including)
Ox_app_suite Open-xchange 7.10.6-rev06 (including) 7.10.6-rev06 (including)
Ox_app_suite Open-xchange 7.10.6-rev07 (including) 7.10.6-rev07 (including)
Ox_app_suite Open-xchange 7.10.6-rev08 (including) 7.10.6-rev08 (including)
Ox_app_suite Open-xchange 7.10.6-rev09 (including) 7.10.6-rev09 (including)
Ox_app_suite Open-xchange 7.10.6-rev10 (including) 7.10.6-rev10 (including)
Ox_app_suite Open-xchange 7.10.6-rev11 (including) 7.10.6-rev11 (including)
Ox_app_suite Open-xchange 7.10.6-rev12 (including) 7.10.6-rev12 (including)
Ox_app_suite Open-xchange 7.10.6-rev13 (including) 7.10.6-rev13 (including)
Ox_app_suite Open-xchange 7.10.6-rev14 (including) 7.10.6-rev14 (including)
Ox_app_suite Open-xchange 7.10.6-rev15 (including) 7.10.6-rev15 (including)
Ox_app_suite Open-xchange 7.10.6-rev16 (including) 7.10.6-rev16 (including)
Ox_app_suite Open-xchange 7.10.6-rev17 (including) 7.10.6-rev17 (including)
Ox_app_suite Open-xchange 7.10.6-rev18 (including) 7.10.6-rev18 (including)
Ox_app_suite Open-xchange 7.10.6-rev19 (including) 7.10.6-rev19 (including)
Ox_app_suite Open-xchange 7.10.6-rev20 (including) 7.10.6-rev20 (including)
Ox_app_suite Open-xchange 7.10.6-rev21 (including) 7.10.6-rev21 (including)
Ox_app_suite Open-xchange 7.10.6-rev22 (including) 7.10.6-rev22 (including)
Ox_app_suite Open-xchange 7.10.6-rev23 (including) 7.10.6-rev23 (including)
Ox_app_suite Open-xchange 7.10.6-rev24 (including) 7.10.6-rev24 (including)
Ox_app_suite Open-xchange 7.10.6-rev25 (including) 7.10.6-rev25 (including)
Ox_app_suite Open-xchange 7.10.6-rev26 (including) 7.10.6-rev26 (including)
Ox_app_suite Open-xchange 7.10.6-rev27 (including) 7.10.6-rev27 (including)
Ox_app_suite Open-xchange 7.10.6-rev28 (including) 7.10.6-rev28 (including)
Ox_app_suite Open-xchange 7.10.6-rev29 (including) 7.10.6-rev29 (including)
Ox_app_suite Open-xchange 7.10.6-rev30 (including) 7.10.6-rev30 (including)
Ox_app_suite Open-xchange 7.10.6-rev31 (including) 7.10.6-rev31 (including)
Ox_app_suite Open-xchange 7.10.6-rev32 (including) 7.10.6-rev32 (including)
Ox_app_suite Open-xchange 7.10.6-rev33 (including) 7.10.6-rev33 (including)
Ox_app_suite Open-xchange 7.10.6-rev34 (including) 7.10.6-rev34 (including)
Ox_app_suite Open-xchange 7.10.6-rev35 (including) 7.10.6-rev35 (including)
Ox_app_suite Open-xchange 7.10.6-rev36 (including) 7.10.6-rev36 (including)

References