PT-2020-13183 · Open Xchange · Ox App Suite
Kattsson
·
Published
2020-08-31
·
Updated
2021-07-21
·
CVE-2020-12645
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OX App Suite versions 7.10.1 through 7.10.3
Description
The issue is related to improper input validation for rate limits, which can be exploited with a crafted User-Agent header. Additionally, it involves spoofed vacation notices and excessive memory consumption through the /apps/load endpoint.
Recommendations
For OX App Suite versions 7.10.1 through 7.10.3, consider updating to a version that addresses the improper input validation issue. As a temporary workaround, restrict access to the /apps/load endpoint to minimize the risk of excessive memory consumption. Avoid using spoofed vacation notices until the issue is resolved.
Fix
Improper Restriction of Excessive Authentication Attempts
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ox App Suite