PT-2020-13183 · Open Xchange · Ox App Suite

Kattsson

·

Published

2020-08-31

·

Updated

2021-07-21

·

CVE-2020-12645

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OX App Suite versions 7.10.1 through 7.10.3
Description The issue is related to improper input validation for rate limits, which can be exploited with a crafted User-Agent header. Additionally, it involves spoofed vacation notices and excessive memory consumption through the /apps/load endpoint.
Recommendations For OX App Suite versions 7.10.1 through 7.10.3, consider updating to a version that addresses the improper input validation issue. As a temporary workaround, restrict access to the /apps/load endpoint to minimize the risk of excessive memory consumption. Avoid using spoofed vacation notices until the issue is resolved.

Fix

Improper Restriction of Excessive Authentication Attempts

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-12645

Affected Products

Ox App Suite