Security Flaw in OX App Suite Affecting User-Defined Templates
CVE-2023-29051
8.1HIGH
What is CVE-2023-29051?
The vulnerability in OX App Suite relates to user-defined OXMF templates, enabling unauthorized access to a segment of the internal Java API. Despite a switch intended to disable this feature by default, it failed to function correctly, resulting in potential exposure to unauthorized users. This oversight allows malicious actors to discover and manipulate sensitive application states, including objects tied to various users and contexts. Remediation efforts involve reinforcing the switch functionality and plans to phase out the template feature in future iterations of the product. No public exploits have been reported at this time.
Affected Version(s)
OX App Suite 0 <= 7.10.6-rev51
OX App Suite 0 <= 8.17