CVE-2023-24604
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published May 29, 2023
Updated: Jan 14, 2025
Summary
CVE-2023-24604 is a vulnerability affecting OX App Suite before version 7.10.6-rev37. This issue allows a maliciously crafted iCal feed to provide an unlimited amount of header data during download. The software fails to check the length of HTTP headers, potentially leading to memory exhaustion or denial-of-service attacks. The vulnerability poses a significant risk, especially in environments where users frequently download iCal feeds. It is recommended that affected organizations upgrade to the latest version of OX App Suite to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- OX App Suite
Affected Vendors
- Open-xchange