Aller au contenu

Fiche vulnérabilité

CVE-2023-29050 : faille critique open-xchange ox app suite (CVSS 9.6)

Description

The optional "LDAP contacts provider" could be abused by privileged users to inject LDAP filter strings that allow to access content outside of the intended hierarchy. Unauthorized users could break confidentiality of information in the directory and potentially cause high load on the directory server, leading to denial of service. Encoding has been added for user-provided fragments that are used when constructing the LDAP query. No publicly available exploits are known.

En bref

Sévérité
Critique (CVSS 9.6)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H
Exploitation active
Non signalée par la CISA
Publication
8 janv. 2024
Dernière mise à jour
17 juin 2026

Produits concernés

  • open-xchange ox app suite

Références

Rechercher une autre vulnérabilité dans la base CVE