CVE-2023-29048
A component for parsing OXMF templates could be abused to execute arbitrary system commands that would be executed as the non-privileged runtime user.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.33%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A component for parsing OXMF templates could be abused to execute arbitrary system commands that would be executed as the non-privileged runtime user. Users and attackers could run system commands with limited privilege to gain unauthorized access to confidential information and potentially violate integrity by modifying resources. The template engine has been reconfigured to deny execution of harmful commands on a system level. No publicly available exploits are known.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.33% probability · 69th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- open-xchange/ox app suite
- Source
- security@open-xchange.com
References
- http://packetstormsecurity.com/files/176421/OX-App-Suite-7.10.6-XSS-Command-Execution-LDAP-Injection.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2024/Jan/3Mailing List, Third Party Advisory
- https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0005.jsonIssue Tracking
- https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6248_7.10.6_2023-09-19.pdfRelease Notes
- http://packetstormsecurity.com/files/176421/OX-App-Suite-7.10.6-XSS-Command-Execution-LDAP-Injection.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2024/Jan/3Mailing List, Third Party Advisory
- https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0005.jsonIssue Tracking
- https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6248_7.10.6_2023-09-19.pdfRelease Notes
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.