MEDIUM
Processing time of drive search expressions now gets monitored, and the related request is terminated if a resource threshold is reached
Published Feb 12, 2024
6.5
MEDIUMCVSS 3.1
EPSS 0.78%
Description
Processing time of drive search expressions now gets monitored, and the related request is terminated if a resource threshold is reached. Availability of OX App Suite could be reduced due to high processing load. Please deploy the provided updates and patch releases. Processing of user-defined drive search expressions is not limited No publicly available exploits are known.
Affected products
-
- Version 0StatusaffectedConstraints<=7.10.6-rev55
- Version 0StatusaffectedConstraints<=7.6.3-rev71
- Version 0StatusaffectedConstraints<=8.19
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Open-Xchange GmbH | OX App Suite | unaffected |
|
OR
- < 7.6.3
- > 7.6.3 · < 7.10.6
- > 7.10.6 · < 8.20
- 7.6.3
- 7.6.3
- 7.6.3
- 7.6.3
- 7.6.3
- 7.6.3
- 7.6.3
- 7.6.3
- 7.6.3
- 7.6.3
- 7.6.3
- 7.6.3
- 7.6.3
- 7.6.3
- 7.6.3
- 7.6.3
- 7.6.3
- 7.6.3
- 7.6.3
- 7.6.3
- 7.6.3
- 7.6.3
- 7.6.3
- 7.6.3
- 7.6.3
- 7.6.3
- 7.6.3
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
- 7.10.6
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- http://seclists.org/fulldisclosure/2024/Feb/10
- https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0007.json vendor-advisoryVendor Advisory
- https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6259_7.10.6_2023-12-11.pdf release-notesRelease Notes
| Link | Providers | Tags |
|---|---|---|
| http://seclists.org/fulldisclosure/2024/Feb/10 | ||
| https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0007.json | vendor-advisoryVendor Advisory | |
| https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6259_7.10.6_2023-12-11.pdf | release-notesRelease Notes |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner OX
Published Feb 12, 2024
Updated Nov 4, 2025
Reserved Aug 30, 2023
Link CVE-2023-41706
CISA Vulnrichment
Updated Feb 12, 2024