Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-23193

Опубликовано: 06 мая 2024
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

E-Mails exported as PDF were stored in a cache that did not consider specific session information for the related user account. Users of the same service node could access other users E-Mails in case they were exported as PDF for a brief moment until caches were cleared. Successful exploitation requires good timing and modification of multiple request parameters. Please deploy the provided updates and patch releases. The cache for PDF exports now takes user session information into consideration when performing authorization decisions. No publicly available exploits are known.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:open-xchange:ox_app_suite:*:*:*:*:*:*:*:*
Версия до 8.22 (исключая)

EPSS

Процентиль: 35%
0.00146
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200
CWE-384

Связанные уязвимости

CVSS3: 5.3
github
почти 2 года назад

E-Mails exported as PDF were stored in a cache that did not consider specific session information for the related user account. Users of the same service node could access other users E-Mails in case they were exported as PDF for a brief moment until caches were cleared. Successful exploitation requires good timing and modification of multiple request parameters. Please deploy the provided updates and patch releases. The cache for PDF exports now takes user session information into consideration when performing authorization decisions. No publicly available exploits are known.

EPSS

Процентиль: 35%
0.00146
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200
CWE-384