PT-2024-12963 · Unknown · Ox App Suite
Published
2024-02-12
·
Updated
2024-10-17
·
CVE-2023-41705
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
OX App Suite (affected versions not specified)
Description
The issue arises from the processing of user-defined DAV user-agent strings not being limited, which could lead to a high processing load and reduce the availability of OX App Suite. To address this, updates and patch releases have been provided. With these updates, the processing time of DAV user-agents is now monitored, and any related request is terminated if a resource threshold is reached. There are no known publicly available exploits for this issue.
Recommendations
Please deploy the provided updates and patch releases to resolve the issue.
As a temporary workaround, consider monitoring the processing time of DAV user-agents and terminating requests that exceed resource thresholds until a patch is fully applied.
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ox App Suite