First published: Thu Nov 02 2023(Updated: )
Connections to external data sources, like e-mail autoconfiguration, were not terminated in case they hit a timeout, instead those connections were logged. Some connections use user-controlled endpoints, which could be malicious and attempt to keep the connection open for an extended period of time. As a result users were able to trigger large amount of egress network connections, possibly exhausting network pool resources and lock up legitimate requests. A new mechanism has been introduced to cancel external connections that might access user-controlled endpoints. No publicly available exploits are known.
Credit: security@open-xchange.com
Affected Software | Affected Version | How to fix |
---|---|---|
<7.10.6 | ||
=7.10.6 | ||
=7.10.6-patch_release_6069 | ||
=7.10.6-patch_release_6073 | ||
=7.10.6-patch_release_6080 | ||
=7.10.6-patch_release_6085 | ||
=7.10.6-patch_release_6093 | ||
=7.10.6-patch_release_6102 | ||
=7.10.6-patch_release_6112 | ||
=7.10.6-patch_release_6121 | ||
=7.10.6-patch_release_6133 | ||
=7.10.6-patch_release_6138 | ||
=7.10.6-patch_release_6141 | ||
=7.10.6-patch_release_6146 | ||
=7.10.6-patch_release_6147 | ||
=7.10.6-patch_release_6148 | ||
=7.10.6-patch_release_6150 | ||
=7.10.6-patch_release_6156 | ||
=7.10.6-patch_release_6161 | ||
=7.10.6-patch_release_6166 | ||
=7.10.6-patch_release_6173 | ||
=7.10.6-patch_release_6176 | ||
=7.10.6-patch_release_6178 | ||
=7.10.6-patch_release_6189 | ||
=7.10.6-patch_release_6194 | ||
=7.10.6-patch_release_6199 | ||
=7.10.6-patch_release_6204 | ||
=7.10.6-patch_release_6205 | ||
=7.10.6-patch_release_6209 | ||
=7.10.6-patch_release_6210 | ||
=7.10.6-patch_release_6214 | ||
=7.10.6-patch_release_6215 | ||
=7.10.6-patch_release_6216 | ||
=7.10.6-patch_release_6218 | ||
=7.10.6-patch_release_6219 | ||
=7.10.6-patch_release_6220 | ||
=7.10.6-patch_release_6227 | ||
=7.10.6-patch_release_6230 | ||
=7.10.6-patch_release_6233 | ||
=7.10.6-patch_release_6235 | ||
=7.10.6-patch_release_6236 | ||
=7.10.6-patch_release_6239 | ||
=7.10.6-patch_release_6241 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-29046 is a vulnerability where connections to external data sources, like e-mail autoconfiguration, were not terminated in case they hit a timeout and instead were logged.
The severity of CVE-2023-29046 is medium, with a severity value of 4.3.
Open-xchange Open-xchange Appsuite versions up to 7.10.6 are affected by CVE-2023-29046.
To fix CVE-2023-29046, it is recommended to update to Open-xchange Open-xchange Appsuite version 7.10.6-patch_release_6243 or later.