PT-2024-20106 · Mailcow · Mailcow

0Xbunniee

·

Published

2024-02-02

·

Updated

2024-02-10

·

CVE-2024-23824

CVSS v3.1

4.7

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions mailcow versions 2023-12a and prior
Description The application is vulnerable to a pixel flood attack. Once the payload has been successfully uploaded in the logo, the application becomes slow and unresponsive in the admin page.
Recommendations For versions 2023-12a and prior, update to version 2024-01 to resolve the issue. As a temporary workaround, consider restricting the upload of logos to minimize the risk of exploitation.

Exploit

Fix

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2024-23824
GHSA-45RV-3C5P-W4H7

Affected Products

Mailcow