CVE-2023-26442
3.2
Vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N
Exploitability: 1.4 / Impact: 1.4
Source: NVD
Description
In case Cacheservice was configured to use a sproxyd object-storage backend, it would follow HTTP redirects issued by that backend. An attacker with access to a local or restricted network with the capability to intercept and replay HTTP requests to sproxyd (or who is in control of the sproxyd service) could perform a server-side request-forgery attack and make Cacheservice connect to unexpected resources. We have disabled the ability to follow HTTP redirects when connecting to sproxyd resources. No publicly available exploits are known.
Affected (1)
Products: Open Xchange: Open Xchange Appsuite Office
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 8.11 |
References (8)
Source: security@open-xchange.com
Third Party AdvisoryVDB Entry
Source: security@open-xchange.com
Mailing ListThird Party Advisory
Source: security@open-xchange.com
Source: security@open-xchange.com
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes
Timeline
No history available yet.