Vulnerabilities (CVE)

Filtered by vendor Open-xchange Subscribe
Filtered by product Open-xchange Appsuite Office
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-26442 1 Open-xchange 1 Open-xchange Appsuite Office 2024-01-12 N/A 3.2 LOW
In case Cacheservice was configured to use a sproxyd object-storage backend, it would follow HTTP redirects issued by that backend. An attacker with access to a local or restricted network with the capability to intercept and replay HTTP requests to sproxyd (or who is in control of the sproxyd service) could perform a server-side request-forgery attack and make Cacheservice connect to unexpected resources. We have disabled the ability to follow HTTP redirects when connecting to sproxyd resources. No publicly available exploits are known.