CVE-2023-26451

HIGH

OAuth Authorization Service - Info Disclosure

Title source: llm
STIX 2.1

Description

Functions with insufficient randomness were used to generate authorization tokens of the integrated oAuth Authorization Service. Authorization codes were predictable for third parties and could be used to intercept and take over the client authorization process. As a result, other users accounts could be compromised. The oAuth Authorization Service is not enabled by default. We have updated the implementation to use sources with sufficient randomness to generate authorization tokens. No publicly available exploits are known.

Scores

CVSS v3 7.5
EPSS 0.0011
EPSS Percentile 28.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-330
Status published
Products (1)
open-xchange/open-xchange_appsuite_backend < 8.11.0
Published Aug 02, 2023
Tracked Since Feb 18, 2026