CVE-2014-2391Sensitive Information Exposure in Appsuite

Severity
4.3MEDIUMNVD
EPSS
0.2%
top 54.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 24
Latest updateMay 17

Description

The password recovery service in Open-Xchange AppSuite before 7.2.2-rev20, 7.4.1 before 7.4.1-rev11, and 7.4.2 before 7.4.2-rev13 makes an improper decision about the sensitivity of a string representing a previously used but currently invalid password, which allows remote attackers to obtain potentially useful password-pattern information by reading (1) a web-server access log, (2) a web-server Referer log, or (3) browser history that contains this string because of its presence in a GET reques

CVSS vector

AV:N/AC:M/C:P/I:N/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-gp48-6mgh-cg4v: The password recovery service in Open-Xchange AppSuite before 72022-05-17
CVEList
CVE-2014-2391: The password recovery service in Open-Xchange AppSuite before 72014-04-17
CVE-2014-2391 — Sensitive Information Exposure | cvebase