Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-26451

Опубликовано: 02 авг. 2023
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

Functions with insufficient randomness were used to generate authorization tokens of the integrated oAuth Authorization Service. Authorization codes were predictable for third parties and could be used to intercept and take over the client authorization process. As a result, other users accounts could be compromised. The oAuth Authorization Service is not enabled by default. We have updated the implementation to use sources with sufficient randomness to generate authorization tokens. No publicly available exploits are known.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:open-xchange:open-xchange_appsuite_backend:*:*:*:*:*:*:*:*
Версия до 8.11.0 (включая)

EPSS

Процентиль: 25%
0.00087
Низкий

7.5 High

CVSS3

Дефекты

CWE-330
CWE-330

Связанные уязвимости

CVSS3: 7.5
github
больше 2 лет назад

Functions with insufficient randomness were used to generate authorization tokens of the integrated oAuth Authorization Service. Authorization codes were predictable for third parties and could be used to intercept and take over the client authorization process. As a result, other users accounts could be compromised. The oAuth Authorization Service is not enabled by default. We have updated the implementation to use sources with sufficient randomness to generate authorization tokens. No publicly available exploits are known.

EPSS

Процентиль: 25%
0.00087
Низкий

7.5 High

CVSS3

Дефекты

CWE-330
CWE-330