OX App Suite before backend 7.10.6-rev37 does not check HTTP header lengths when downloading, e.g., potentially allowing a crafted iCal feed to provide an unlimited amount of header data.
References
Link | Resource |
---|---|
http://seclists.org/fulldisclosure/2023/May/3 | Mailing List Third Party Advisory |
https://open-xchange.com | Product |
http://seclists.org/fulldisclosure/2023/May/3 | Mailing List Third Party Advisory |
https://open-xchange.com | Product |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 07:48
Type | Values Removed | Values Added |
---|---|---|
References | () http://seclists.org/fulldisclosure/2023/May/3 - Mailing List, Third Party Advisory | |
References | () https://open-xchange.com - Product |
Information
Published : 2023-05-29 03:15
Updated : 2025-01-14 18:15
NVD link : CVE-2023-24604
Mitre link : CVE-2023-24604
CVE.ORG link : CVE-2023-24604
JSON object : View
Products Affected
open-xchange
- ox_app_suite
CWE