Security Advisories for OX App Suite are published to help operators identify mitigations for vulnerabilities and to assess the impact on a specific deployment. Solutions for vulnerabilities are provided well ahead of public disclosure to reduce the risk of exploitation.
To get in contact with the security team, please use the information from our RFC9116 resource at open-xchange.com.
Details on vulnerabilities are published after a reasonable time has passed for operators and software distributions to provide and integrate security updates. This embargo time spans at least 15 and maximum 90 days after providing a security update.
VDP and Bug Bounty
Public vulnerability disclosure policy and bug-bounty programs are available to report qualifying vulnerabilities. Please see vdp.open-xchange.com for more details.
As a CVE CNA Open-Xchange takes ownership of assigning and managing CVE IDs for its entire product range. Each recognized vulnerability gets a unique CVE ID assigned, and information for the CVE record is published when security advisories become public.
If you have discovered a vulnerability in any of our products, please get in touch to have a CVE assigned and coordinate the disclosure process.
Open-Xchange is committed to implementing industry standards and to improving security automation. Advisories are published using the CSAF framework, and Open-Xchange is a trusted CSAF provider. Machine-readable information on distribution and signing can be found at our provider-metadata.json.
CSAF documents with security advisories for OX App Suite 7 use
x_generic_uris that provide a custom
uri attribute which has a value like
1234 is a 4 digit reference number used to identify related patch releases as published in our release notes documentation.
Please find security advisories for other parts of our product range at their respective documentation portals.