PT-2023-19707 · Open Xchange · Ox App Suite
Tim Coen
·
Published
2023-05-29
·
Updated
2025-01-14
·
CVE-2023-24605
CVSS v3.1
4.2
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
OX App Suite versions prior to 7.10.6-rev37
Description
The issue concerns the lack of enforcement of two-factor authentication (2FA) for all endpoints in OX App Suite. Specifically, endpoints such as reading from a drive, reading contact data, and renaming tokens are not properly secured with 2FA. This oversight could potentially allow unauthorized access to sensitive data.
Recommendations
For versions prior to 7.10.6-rev37, update to version 7.10.6-rev37 or later to ensure 2FA is enforced for all endpoints. As a temporary workaround, consider restricting access to sensitive endpoints, such as those related to drive access, contact data, and token management, until the update can be applied.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ox App Suite