PT-2024-12965 · Unknown · Ox App Suite

Published

2024-02-12

·

Updated

2024-10-17

·

CVE-2023-41707

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OX App Suite (affected versions not specified)
Description The issue arises from the processing of user-defined mail search expressions without limitations, potentially reducing the availability of OX App Suite due to high processing load. The processing time of mail search expressions is now monitored, and related requests are terminated if a resource threshold is reached. No publicly available exploits are known.
Recommendations To resolve the issue, please deploy the provided updates and patch releases. As a temporary workaround, consider monitoring the processing time of mail search expressions and terminating related requests if a resource threshold is reached. Restrict access to the mail search functionality to minimize the risk of exploitation until the updates are deployed.

Fix

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2023-41707

Affected Products

Ox App Suite