René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

81 lines
2.3 KiB
JSON

{
"id": "CVE-2022-29851",
"sourceIdentifier": "cve@mitre.org",
"published": "2022-10-25T17:15:51.937",
"lastModified": "2022-10-26T02:11:55.477",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "documentconverter in OX App Suite through 7.10.6, in a non-default configuration with ghostscript, allows OS Command Injection because file conversion may occur for an EPS document that is disguised as a PDF document."
},
{
"lang": "es",
"value": "documentconverter en OX App Suite versiones hasta 7.10.6, en una configuraci\u00f3n no predeterminada con ghostscript, permite una inyecci\u00f3n de comandos del sistema operativo porque la conversi\u00f3n de archivos puede ocurrir para un documento EPS que se disfraza como un documento PDF"
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL"
},
"exploitabilityScore": 3.9,
"impactScore": 5.9
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-78"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:open-xchange:ox_app_suite:*:*:*:*:*:*:*:*",
"versionEndIncluding": "7.10.6",
"matchCriteriaId": "BF6F4137-FC0E-461F-B0D2-21FE310B6183"
}
]
}
]
}
],
"references": [
{
"url": "https://packetstormsecurity.com/files/168242/OX-App-Suite-Cross-Site-Scripting-Command-Injection.html",
"source": "cve@mitre.org",
"tags": [
"Third Party Advisory",
"VDB Entry"
]
}
]
}