« Volver al listado

CVE-2023-29043

Estado: ModificadaMedia (6.1)—

Presentations may contain references to images, which are user-controlled, and could include malicious script code that is being processed when editing a document. Script code embedded in malicious documents could be executed in the context of the user editing the document when performing certain actions, like copying content. The relevant attribute does now get encoded to avoid the possibility of executing script code. No publicly available exploits are known.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-29043",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-29043",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-01-18T19:22:25.304395Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@open-xchange.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@open-xchange.com",
      "affectedData": [
        {
          "vendor": "OX Software GmbH",
          "modules": [
            "office"
          ],
          "product": "OX App Suite",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "semver",
              "lessThanOrEqual": "7.10.6-rev7"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-11-02T14:15:11.017",
  "references": [
    {
      "url": "https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0004.json",
      "source": "security@open-xchange.com"
    },
    {
      "url": "https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6243_7.10.6_2023-08-01.pdf",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "security@open-xchange.com"
    },
    {
      "url": "https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0004.json",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6243_7.10.6_2023-08-01.pdf",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@open-xchange.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Presentations may contain references to images, which are user-controlled, and could include malicious script code that is being processed when editing a document. Script code embedded in malicious documents could be executed in the context of the user editing the document when performing certain actions, like copying content. The relevant attribute does now get encoded to avoid the possibility of executing script code. No publicly available exploits are known.\n\n"
    },
    {
      "lang": "es",
      "value": "Las presentaciones pueden contener referencias a imágenes controladas por el usuario y podrían incluir código de script malicioso que se procesa al editar un documento. El código de script incorporado en documentos maliciosos podría ejecutarse en el contexto en el que el usuario edita el documento al realizar determinadas acciones, como copiar contenido. El atributo relevante ahora se codifica para evitar la posibilidad de ejecutar código de script. No se conocen exploits disponibles públicamente."
    }
  ],
  "lastModified": "2026-06-17T05:49:14.270",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "59D4F30E-2F52-4948-9C69-C57472833C79",
              "versionEndExcluding": "7.10.6"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A144D75D-60A8-4EE0-813C-F658C626B2AA"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6069:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2DA66230-DE02-4881-A893-E9E78286B157"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6073:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "955F3DFB-6479-4867-B62A-82730DBEB498"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6080:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "327D1B56-0D05-4D99-91D4-CC1F0AC32972"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6085:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D0CD0684-C431-47F8-A2F4-1936D5C5A72B"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6093:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EAA6A4A7-C1EE-4716-9F4D-2FF4C4D5FEC8"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6102:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D0968764-CCEE-47A7-9111-E106D887DA43"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6112:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "16589FBB-F0CD-4041-8141-5C89FCCA72AF"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6121:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3CB877EE-A5FE-4FF7-9D21-5C1CFA7343D4"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6133:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0DF5FB90-8D6D-4F99-B454-411B1DFFA630"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6138:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F58876B9-6C2E-4048-A793-B441A84E86F5"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6141:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D5F177CB-CC45-45A0-9D02-C14A13ECC7A3"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6146:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A89A4192-54E9-4899-8C7B-6C7F7E650D5C"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6147:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F2DC1357-9CD5-415F-A190-2F3F4498EF96"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6148:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D78ACF64-2802-44DD-AF7A-1BD5EA7F9908"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6150:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E8F675FA-1684-413A-B1BE-1C5434AC2862"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6156:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F3F1FDC3-35B2-4BDB-A685-75BC72588179"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6161:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5B1E509D-2F41-4296-86D2-6BD71783060F"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6166:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AC93EA37-F341-45EC-B651-4F326FB8C613"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6173:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1A4DB8A6-1702-462C-BFCB-39F91D2EFCE1"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6176:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FC0AEFDB-D033-47FC-93FC-8652F922BB8C"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6178:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B5354768-6527-43C2-B492-A8C14AB4E784"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6189:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D83F26D1-B8C6-4114-81EC-810DD5412DC8"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6194:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E9EBC010-9963-4636-96F7-A121FCF755A7"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6199:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F626D64B-C301-4CD8-94B4-48689BD3F29C"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6204:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5E32810C-7B35-42F1-BCA5-E10C02BE2215"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6205:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6539D059-8614-4C26-93C4-C2DDCC5D35E2"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6209:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E359EE75-A2F9-479B-B757-CAE1064AB8F4"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6210:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0BCABDEF-D292-406E-B53C-AFF22484E916"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6214:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ABE8872C-B1DD-4A45-8EF8-E8C355CA6C54"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6215:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "44B20B83-833A-4C68-8693-365BD046C157"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6216:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E254E6D1-D18E-4A2A-A2FF-7D03F39E65DD"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6218:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5F0C5E53-4D15-425A-B4CF-5869353724BF"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6219:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2F4BF5F1-F316-4BAC-83E0-DEAC8C50754E"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6220:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5CDD03A8-5B86-4B87-9C29-6C967261C5C0"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6227:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6071E15F-4D59-41DC-A4D4-7D1AA392A1F2"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6230:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C72C1CEB-7BF7-4A5F-B2E9-397F86CCBF4E"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6233:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5B0F0218-4224-4084-B38D-9719D3782C03"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6235:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BFC41329-1AD6-4575-A22D-977EC5539DA4"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6236:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "217A06B7-0823-4508-BC0C-AD792BA88F7B"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6239:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "246E98B2-A6C8-4410-AA6A-7E81EE8C5E76"
            },
            {
              "criteria": "cpe:2.3:a:open-xchange:open-xchange_appsuite:7.10.6:patch_release_6241:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "74D1EC02-D009-45DA-B1EC-2219E0F0183C"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@open-xchange.com"
}