First published: Mon May 29 2023(Updated: )
OX App Suite before backend 7.10.6-rev37 does not check HTTP header lengths when downloading, e.g., potentially allowing a crafted iCal feed to provide an unlimited amount of header data.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Open-xchange Ox App Suite | =7.10.6-rev01 | |
Open-xchange Ox App Suite | =7.10.6-rev02 | |
Open-xchange Ox App Suite | =7.10.6-rev03 | |
Open-xchange Ox App Suite | =7.10.6-rev04 | |
Open-xchange Ox App Suite | =7.10.6-rev05 | |
Open-xchange Ox App Suite | =7.10.6-rev06 | |
Open-xchange Ox App Suite | =7.10.6-rev07 | |
Open-xchange Ox App Suite | =7.10.6-rev08 | |
Open-xchange Ox App Suite | =7.10.6-rev09 | |
Open-xchange Ox App Suite | =7.10.6-rev10 | |
Open-xchange Ox App Suite | =7.10.6-rev11 | |
Open-xchange Ox App Suite | =7.10.6-rev12 | |
Open-xchange Ox App Suite | =7.10.6-rev13 | |
Open-xchange Ox App Suite | =7.10.6-rev14 | |
Open-xchange Ox App Suite | =7.10.6-rev15 | |
Open-xchange Ox App Suite | =7.10.6-rev16 | |
Open-xchange Ox App Suite | =7.10.6-rev17 | |
Open-xchange Ox App Suite | =7.10.6-rev18 | |
Open-xchange Ox App Suite | =7.10.6-rev19 | |
Open-xchange Ox App Suite | =7.10.6-rev20 | |
Open-xchange Ox App Suite | =7.10.6-rev21 | |
Open-xchange Ox App Suite | =7.10.6-rev22 | |
Open-xchange Ox App Suite | =7.10.6-rev23 | |
Open-xchange Ox App Suite | =7.10.6-rev24 | |
Open-xchange Ox App Suite | =7.10.6-rev25 | |
Open-xchange Ox App Suite | =7.10.6-rev26 | |
Open-xchange Ox App Suite | =7.10.6-rev27 | |
Open-xchange Ox App Suite | =7.10.6-rev28 | |
Open-xchange Ox App Suite | =7.10.6-rev29 | |
Open-xchange Ox App Suite | =7.10.6-rev30 | |
Open-xchange Ox App Suite | <7.10.6 | |
Open-xchange Ox App Suite | =7.10.6 | |
Open-xchange Ox App Suite | =7.10.6-rev37 | |
Open-xchange Ox App Suite | =7.10.6-rev36 | |
Open-xchange Ox App Suite | =7.10.6-rev35 | |
Open-xchange Ox App Suite | =7.10.6-rev34 | |
Open-xchange Ox App Suite | =7.10.6-rev33 | |
Open-xchange Ox App Suite | =7.10.6-rev32 | |
Open-xchange Ox App Suite | =7.10.6-rev31 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-24604.
The severity of CVE-2023-24604 is medium with a CVSS score of 4.3.
The affected software is Open-xchange Ox App Suite version 7.10.6-rev01 to 7.10.6-rev37.
CVE-2023-24604 allows a crafted iCal feed to provide an unlimited amount of header data when downloading in OX App Suite before backend 7.10.6-rev37, potentially leading to security issues.
Yes, updating to Open-xchange Ox App Suite backend version 7.10.6-rev37 or higher fixes the vulnerability.