PT-2024-12965 · Unknown · Ox App Suite
Published
2024-02-12
·
Updated
2024-10-17
·
CVE-2023-41707
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
OX App Suite (affected versions not specified)
Description
The issue arises from the processing of user-defined mail search expressions without limitations, potentially reducing the availability of OX App Suite due to high processing load. The processing time of mail search expressions is now monitored, and related requests are terminated if a resource threshold is reached. No publicly available exploits are known.
Recommendations
To resolve the issue, please deploy the provided updates and patch releases. As a temporary workaround, consider monitoring the processing time of mail search expressions and terminating related requests if a resource threshold is reached. Restrict access to the mail search functionality to minimize the risk of exploitation until the updates are deployed.
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ox App Suite