Description
Mattermost fails to limit the amount of data extracted from compressed archives during board import in Mattermost Boards allowing an attacker to consume excessive resources, possibly leading to Denial of Service, by importing a board using a specially crafted zip (zip bomb).

Published: 2023-11-27
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Update Mattermost Server to versions 9.1.1, 9.0.2, 7.8.13, 8.1.4 or higher.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-2981 Mattermost fails to limit the amount of data extracted from compressed archives during board import in Mattermost Boards allowing an attacker to consume excessive resources, possibly leading to Denial of Service, by importing a board using a specially crafted zip (zip bomb).
Github GHSA Github GHSA GHSA-j4c3-3h73-74m9 Mattermost Uncontrolled Resource Consumption vulnerability
References
History

Mon, 02 Dec 2024 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Mattermost Mattermost
cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2024-12-02T19:33:50.978Z

Reserved: 2023-11-22T11:18:57.625Z

Link: CVE-2023-48268

cve-icon Vulnrichment

Updated: 2024-08-02T21:23:39.504Z

cve-icon NVD

Status : Modified

Published: 2023-11-27T10:15:08.217

Modified: 2024-11-21T08:31:22.667

Link: CVE-2023-48268

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses