CVE-2023-29046
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Connections to external data sources, like e-mail autoconfiguration, were not terminated in case they hit a timeout, instead those connections were logged. Some connections use user-controlled endpoints, which could be malicious and attempt to keep the connection open for an extended period of time. As a result users were able to trigger large amount of egress network connections, possibly exhausting network pool resources and lock up legitimate requests. A new mechanism has been introduced to cancel external connections that might access user-controlled endpoints. No publicly available exploits are known.
Las conexiones a fuentes de datos externas, como la configuración automática de correo electrónico, no finalizaban en caso de que se agotara el tiempo de espera, sino que esas conexiones se registraban. Algunas conexiones utilizan endpoints controlados por el usuario, que podrían ser maliciosos e intentar mantener la conexión abierta durante un período prolongado. Como resultado, los usuarios pudieron activar una gran cantidad de conexiones de red de salida, lo que posiblemente agotó los recursos del grupo de redes y bloqueó solicitudes legítimas. Se ha introducido un nuevo mecanismo para cancelar conexiones externas que podrían acceder a endpoints controlados por el usuario. No se conocen exploits disponibles públicamente.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-03-30 CVE Reserved
- 2023-11-02 CVE Published
- 2024-08-02 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-400: Uncontrolled Resource Consumption
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | < 7.10.6 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version " < 7.10.6" | - |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.10.6 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.10.6" | - |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.10.6 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.10.6" | patch_release_6069 |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.10.6 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.10.6" | patch_release_6073 |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.10.6 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.10.6" | patch_release_6080 |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.10.6 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.10.6" | patch_release_6085 |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.10.6 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.10.6" | patch_release_6093 |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.10.6 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.10.6" | patch_release_6102 |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.10.6 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.10.6" | patch_release_6112 |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.10.6 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.10.6" | patch_release_6121 |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.10.6 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.10.6" | patch_release_6133 |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.10.6 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.10.6" | patch_release_6138 |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.10.6 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.10.6" | patch_release_6141 |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.10.6 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.10.6" | patch_release_6146 |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.10.6 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.10.6" | patch_release_6147 |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.10.6 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.10.6" | patch_release_6148 |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.10.6 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.10.6" | patch_release_6150 |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.10.6 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.10.6" | patch_release_6156 |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.10.6 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.10.6" | patch_release_6161 |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.10.6 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.10.6" | patch_release_6166 |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.10.6 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.10.6" | patch_release_6173 |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.10.6 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.10.6" | patch_release_6176 |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.10.6 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.10.6" | patch_release_6178 |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.10.6 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.10.6" | patch_release_6189 |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.10.6 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.10.6" | patch_release_6194 |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.10.6 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.10.6" | patch_release_6199 |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.10.6 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.10.6" | patch_release_6204 |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.10.6 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.10.6" | patch_release_6205 |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.10.6 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.10.6" | patch_release_6209 |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.10.6 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.10.6" | patch_release_6210 |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.10.6 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.10.6" | patch_release_6214 |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.10.6 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.10.6" | patch_release_6215 |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.10.6 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.10.6" | patch_release_6216 |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.10.6 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.10.6" | patch_release_6218 |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.10.6 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.10.6" | patch_release_6219 |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.10.6 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.10.6" | patch_release_6220 |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.10.6 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.10.6" | patch_release_6227 |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.10.6 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.10.6" | patch_release_6230 |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.10.6 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.10.6" | patch_release_6233 |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.10.6 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.10.6" | patch_release_6235 |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.10.6 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.10.6" | patch_release_6236 |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.10.6 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.10.6" | patch_release_6239 |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.10.6 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.10.6" | patch_release_6241 |
Affected
|