First published: Mon Feb 12 2024(Updated: )
Processing of user-defined mail search expressions is not limited. Availability of OX App Suite could be reduced due to high processing load. Please deploy the provided updates and patch releases. Processing time of mail search expressions now gets monitored, and the related request is terminated if a resource threshold is reached. No publicly available exploits are known.
Credit: security@open-xchange.com
Affected Software | Affected Version | How to fix |
---|---|---|
Open-Xchange App Suite Backend | <7.6.3 | |
Open-Xchange App Suite Backend | >7.6.3<7.10.6 | |
Open-Xchange App Suite Backend | >7.10.6<8.20 | |
Open-Xchange App Suite Backend | =7.6.3 | |
Open-Xchange App Suite Backend | =7.6.3-patch_release_3464 | |
Open-Xchange App Suite Backend | =7.6.3-patch_release_3519 | |
Open-Xchange App Suite Backend | =7.6.3-patch_release_3569 | |
Open-Xchange App Suite Backend | =7.6.3-patch_release_3627 | |
Open-Xchange App Suite Backend | =7.6.3-patch_release_3728 | |
Open-Xchange App Suite Backend | =7.6.3-patch_release_3875 | |
Open-Xchange App Suite Backend | =7.6.3-patch_release_3922 | |
Open-Xchange App Suite Backend | =7.6.3-patch_release_3949 | |
Open-Xchange App Suite Backend | =7.6.3-patch_release_3991 | |
Open-Xchange App Suite Backend | =7.6.3-patch_release_4047 | |
Open-Xchange App Suite Backend | =7.6.3-patch_release_4133 | |
Open-Xchange App Suite Backend | =7.6.3-patch_release_4423 | |
Open-Xchange App Suite Backend | =7.6.3-patch_release_4470 | |
Open-Xchange App Suite Backend | =7.6.3-patch_release_4552 | |
Open-Xchange App Suite Backend | =7.6.3-patch_release_4667 | |
Open-Xchange App Suite Backend | =7.6.3-patch_release_4750 | |
Open-Xchange App Suite Backend | =7.6.3-patch_release_4789 | |
Open-Xchange App Suite Backend | =7.6.3-patch_release_4839 | |
Open-Xchange App Suite Backend | =7.6.3-patch_release_4860 | |
Open-Xchange App Suite Backend | =7.6.3-patch_release_4895 | |
Open-Xchange App Suite Backend | =7.6.3-patch_release_5104 | |
Open-Xchange App Suite Backend | =7.6.3-patch_release_5165 | |
Open-Xchange App Suite Backend | =7.6.3-patch_release_5231 | |
Open-Xchange App Suite Backend | =7.6.3-patch_release_5537 | |
Open-Xchange App Suite Backend | =7.6.3-patch_release_5637 | |
Open-Xchange App Suite Backend | =7.6.3-patch_release_5910 | |
Open-Xchange App Suite Backend | =7.10.6 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6069 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6073 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6080 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6085 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6093 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6102 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6112 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6121 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6133 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6138 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6141 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6146 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6147 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6148 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6150 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6156 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6161 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6166 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6173 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6176 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6178 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6189 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6194 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6199 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6204 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6205 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6209 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6210 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6214 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6215 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6216 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6218 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6219 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6220 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6227 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6230 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6233 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6235 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6236 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6239 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6241 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6243 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6245 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6248 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6249 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6250 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6251 | |
Open-Xchange App Suite Backend | =7.10.6-patch_release_6255 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-41707 is considered a moderate severity vulnerability due to its potential impact on the availability of the OX App Suite.
To fix CVE-2023-41707, you should deploy the provided updates and patch releases as directed by Open-Xchange.
CVE-2023-41707 affects various versions of Open-Xchange App Suite, specifically versions between 7.6.3 and 7.10.6.
The impact of CVE-2023-41707 can lead to reduced availability of email services in OX App Suite due to high processing loads from user-defined mail search expressions.
Yes, several patch releases are available for CVE-2023-41707, including those specific to versions 7.6.3 and 7.10.6.