Overview
Security Advisories for OX App Suite are published to help operators identify mitigations for vulnerabilities and to assess the impact on a specific deployment. Solutions for vulnerabilities are provided well ahead of public disclosure to reduce the risk of exploitation.
This page is the authoritative source for security advisories. Resources are available in CSAF, HTML, Markdown and plain-text format.
Coordinated disclosure
Details on vulnerabilities are published after a reasonable time has passed for operators and software distributions to provide and integrate security updates. This embargo time spans at least 15 and maximum 90 days after providing a security update.
Advisories are publicly shared on this website, CVE.org and the fulldisclosure mailing-list.
VDP and Bug Bounty
Public vulnerability disclosure policy and bug-bounty programs are available to report qualifying vulnerabilities. Please see vdp.open-xchange.com for more details.
CVE
As a CVE CNA Open-Xchange takes ownership of assigning and managing CVE IDs for its entire product range. Each recognized vulnerability gets a unique CVE ID assigned, and information for the CVE record is published when security advisories become public.
If you have discovered a vulnerability in any of our products, please get in touch to have a CVE assigned and coordinate the disclosure process.
CSAF
Open-Xchange is committed to implementing industry standards and to improving security automation. Advisories are published using the CSAF framework, and Open-Xchange is a trusted CSAF provider. Machine-readable information on distribution and signing can be found at our provider-metadata.json.
URN parsing
CSAF documents with security advisories for OX App Suite 7 use x_generic_uris
that provide a custom uri
attribute which has a value like urn:open-xchange:app_suite:patch-id:1234
. 1234
is a 4 digit reference number used to identify related patch releases as published in our release notes documentation.
Other products
Please find security advisories for other parts of our product range at their respective documentation portals.