CVE-2023-26427
20.06.2023, 08:15
Default permissions for a properties file were too permissive. Local system users could read potentially sensitive information. We updated the default permissions for noreply.properties set during package installation. No publicly available exploits are known.Enginsight
| Vendor | Product | Version |
|---|---|---|
| open-xchange | open-xchange_appsuite_backend | 𝑥 < 7.10.6 |
| open-xchange | open-xchange_appsuite_backend | 7.10.6 |
| open-xchange | open-xchange_appsuite_backend | 7.10.6:revision_39 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-922 - Insecure Storage of Sensitive InformationThe software stores sensitive information without properly limiting read or write access by unauthorized actors.
- CWE-732 - Incorrect Permission Assignment for Critical ResourceThe product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
References