Safari Update Fixes Reference Redirect Vulnerability
CVE-2023-41708

5.4MEDIUM

Key Information:

Vendor
CVE Published:
12 February 2024

What is CVE-2023-41708?

The application loader functionality within Open-Xchange Appsuite has been identified as potentially vulnerable to redirect attacks, where an attacker could craft malicious app references. This exploitation route circumvents existing security measures, allowing unauthorized script code injection. To mitigate this risk, it is essential to apply the recommended updates and patch releases, which include stricter controls on app reference handling to prevent relative references and enhance overall application security. Currently, no public exploits have been recorded.

Affected Version(s)

OX App Suite 0 <= 7.10.6-rev38

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.