CVE-2013-2582
Last modified
CVE-2013-2582 is a vulnerability of currently unknown severity. CRLF injection vulnerability in the redirect servlet in Open-Xchange AppSuite and Server before 6.22.0 rev15, 6.22.1 before rev17, 7.0.1 before rev6, and 7.0.2 before rev7 allows remote attackers to inject arbitrary HTTP headers and conduct open redirect attacks by leveraging improper sanitization of whitespace characters.. EPSS estimates a 1.05% chance of exploitation in the next 30 days.
Description
CRLF injection vulnerability in the redirect servlet in Open-Xchange AppSuite and Server before 6.22.0 rev15, 6.22.1 before rev17, 7.0.1 before rev6, and 7.0.2 before rev7 allows remote attackers to inject arbitrary HTTP headers and conduct open redirect attacks by leveraging improper sanitization of whitespace characters.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Open-Xchange | Open-Xchange Appsuite | 6.22.0 |
| Open-Xchange | Open-Xchange Appsuite | 6.22.1 |
| Open-Xchange | Open-Xchange Appsuite | 7.0.1 |
| Open-Xchange | Open-Xchange Appsuite | 7.0.2 |
| Open-Xchange | Open-Xchange Server | 6.22.0 |
| Open-Xchange | Open-Xchange Server | 6.22.1 |
| Open-Xchange | Open-Xchange Server | 7.0.1 |
| Open-Xchange | Open-Xchange Server | 7.0.2 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-2582?
How severe is CVE-2013-2582?
How do I fix CVE-2013-2582?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2013
- CVE-2013-2576Buffer overflow in Artweaver before 3.1.6 allows remote atta…
- CVE-2013-2577Buffer overflow in XnView before 2.04 allows remote attacker…
- CVE-2013-2578cgi-bin/admin/servetest in TP-Link IP Cameras TL-SC3130, TL-…
- CVE-2013-2579TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC31…
- CVE-2013-2580Unrestricted file upload vulnerability in cgi-bin/uploadfile…
- CVE-2013-2581cgi-bin/firmwareupgrade in TP-Link IP Cameras TL-SC3130, TL-…
- CVE-2013-2583Multiple cross-site scripting (XSS) vulnerabilities in Open-…
- CVE-2013-2585Cross-site scripting (XSS) vulnerability in Atmail Webmail S…
- CVE-2013-2586XAMPP 1.8.1 does not properly restrict access to xampp/lang.…
- CVE-2013-2594SQL injection vulnerability in reports/calldiary.php in Horn…
- CVE-2013-2595The device-initialization functionality in the MSM camera dr…
- CVE-2013-2596Integer overflow in the fb_mmap function in drivers/video/fb…7.8
Are you affected by CVE-2013-2582?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
