CVE-2022-37313
Summary
| CVE | CVE-2022-37313 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-12-26 02:15:00 UTC |
| Updated | 2023-01-04 01:59:00 UTC |
| Description | OX App Suite through 7.10.6 allows SSRF because the anti-SSRF protection mechanism only checks the first DNS AA or AAAA record. |
Risk And Classification
Problem Types: CWE-918
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Open-xchange | Open-xchange Appsuite | All | All | All | All |
| Application | Open-xchange | Open-xchange Appsuite | 7.10.5 | - | All | All |
| Application | Open-xchange | Open-xchange Appsuite | 7.10.5 | patch_release_5961 | All | All |
| Application | Open-xchange | Open-xchange Appsuite | 7.10.5 | patch_release_5973 | All | All |
| Application | Open-xchange | Open-xchange Appsuite | 7.10.5 | patch_release_5976 | All | All |
| Application | Open-xchange | Open-xchange Appsuite | 7.10.5 | patch_release_5982 | All | All |
| Application | Open-xchange | Open-xchange Appsuite | 7.10.5 | patch_release_5989 | All | All |
| Application | Open-xchange | Open-xchange Appsuite | 7.10.5 | patch_release_5994 | All | All |
| Application | Open-xchange | Open-xchange Appsuite | 7.10.5 | patch_release_6000 | All | All |
| Application | Open-xchange | Open-xchange Appsuite | 7.10.5 | patch_release_6003 | All | All |
| Application | Open-xchange | Open-xchange Appsuite | 7.10.5 | patch_release_6008 | All | All |
| Application | Open-xchange | Open-xchange Appsuite | 7.10.5 | patch_release_6010 | All | All |
| Application | Open-xchange | Open-xchange Appsuite | 7.10.5 | patch_release_6016 | All | All |
| Application | Open-xchange | Open-xchange Appsuite | 7.10.5 | patch_release_6020 | All | All |
| Application | Open-xchange | Open-xchange Appsuite | 7.10.5 | patch_release_6026 | All | All |
| Application | Open-xchange | Open-xchange Appsuite | 7.10.5 | patch_release_6029 | All | All |
| Application | Open-xchange | Open-xchange Appsuite | 7.10.5 | patch_release_6034 | All | All |
| Application | Open-xchange | Open-xchange Appsuite | 7.10.5 | patch_release_6035 | All | All |
| Application | Open-xchange | Open-xchange Appsuite | 7.10.5 | patch_release_6038 | All | All |
| Application | Open-xchange | Open-xchange Appsuite | 7.10.5 | patch_release_6046 | All | All |
| Application | Open-xchange | Open-xchange Appsuite | 7.10.5 | patch_release_6051 | All | All |
| Application | Open-xchange | Open-xchange Appsuite | 7.10.5 | patch_release_6053 | All | All |
| Application | Open-xchange | Open-xchange Appsuite | 7.10.5 | patch_release_6060 | All | All |
| Application | Open-xchange | Open-xchange Appsuite | 7.10.5 | patch_release_6061 | All | All |
| Application | Open-xchange | Open-xchange Appsuite | 7.10.5 | patch_release_6066 | All | All |
| Application | Open-xchange | Open-xchange Appsuite | 7.10.5 | patch_release_6068 | All | All |
| Application | Open-xchange | Open-xchange Appsuite | 7.10.5 | patch_release_6072 | All | All |
| Application | Open-xchange | Open-xchange Appsuite | 7.10.5 | patch_release_6079 | All | All |
| Application | Open-xchange | Open-xchange Appsuite | 7.10.5 | patch_release_6084 | All | All |
| Application | Open-xchange | Open-xchange Appsuite | 7.10.5 | patch_release_6092 | All | All |
| Application | Open-xchange | Open-xchange Appsuite | 7.10.5 | patch_release_6101 | All | All |
| Application | Open-xchange | Open-xchange Appsuite | 7.10.5 | patch_release_6111 | All | All |
| Application | Open-xchange | Open-xchange Appsuite | 7.10.5 | patch_release_6120 | All | All |
| Application | Open-xchange | Open-xchange Appsuite | 7.10.5 | patch_release_6132 | All | All |
| Application | Open-xchange | Open-xchange Appsuite | 7.10.5 | patch_release_6137 | All | All |
| Application | Open-xchange | Open-xchange Appsuite | 7.10.5 | patch_release_6140 | All | All |
| Application | Open-xchange | Open-xchange Appsuite | 7.10.5 | patch_release_6149 | All | All |
| Application | Open-xchange | Open-xchange Appsuite | 7.10.6 | - | All | All |
| Application | Open-xchange | Open-xchange Appsuite | 7.10.6 | patch_release_6069 | All | All |
| Application | Open-xchange | Open-xchange Appsuite | 7.10.6 | patch_release_6073 | All | All |
| Application | Open-xchange | Open-xchange Appsuite | 7.10.6 | patch_release_6080 | All | All |
| Application | Open-xchange | Open-xchange Appsuite | 7.10.6 | patch_release_6085 | All | All |
| Application | Open-xchange | Open-xchange Appsuite | 7.10.6 | patch_release_6093 | All | All |
| Application | Open-xchange | Open-xchange Appsuite | 7.10.6 | patch_release_6102 | All | All |
| Application | Open-xchange | Open-xchange Appsuite | 7.10.6 | patch_release_6112 | All | All |
| Application | Open-xchange | Open-xchange Appsuite | 7.10.6 | patch_release_6121 | All | All |
| Application | Open-xchange | Open-xchange Appsuite | 7.10.6 | patch_release_6133 | All | All |
| Application | Open-xchange | Open-xchange Appsuite | 7.10.6 | patch_release_6138 | All | All |
| Application | Open-xchange | Open-xchange Appsuite | 7.10.6 | patch_release_6141 | All | All |
| Application | Open-xchange | Open-xchange Appsuite | 7.10.6 | patch_release_6146 | All | All |
| Application | Open-xchange | Open-xchange Appsuite | 7.10.6 | patch_release_6147 | All | All |
| Application | Open-xchange | Open-xchange Appsuite | 7.10.6 | patch_release_6148 | All | All |
| Application | Open-xchange | Open-xchange Appsuite | 7.10.6 | patch_release_6150 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Home | Open-Xchange | MISC | open-xchange.com | |
| Full Disclosure: Open-Xchange Security Advisory 2022-11-24 | CONFIRM | seclists.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.