CVE-2023-29046
CVSS V2 None
CVSS V3 None
Description
Connections to external data sources, like e-mail autoconfiguration, were not terminated in case they hit a timeout, instead those connections were logged. Some connections use user-controlled endpoints, which could be malicious and attempt to keep the connection open for an extended period of time. As a result users were able to trigger large amount of egress network connections, possibly exhausting network pool resources and lock up legitimate requests. A new mechanism has been introduced to cancel external connections that might access user-controlled endpoints. No publicly available exploits are known.
Overview
- CVE ID
- CVE-2023-29046
- Assigner
- OX
- Vulnerability Status
- PUBLISHED
- Published Version
- 2023-11-02T13:01:39.521Z
- Last Modified Date
- 2024-01-12T07:08:22.530Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6243_7.10.6_2023-08-01.pdf | release-notes |
https://documentation.open-xchange.com/appsuite/security/advisories/csaf/2023/oxas-adv-2023-0004.json | vendor-advisory |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-29046 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29046 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-25 04:11:14 | Added to TrackCVE |