Description
Mattermost fails to enforce character limits in all possible notification props allowing an attacker to send a really long value for a notification_prop resulting in the server consuming an abnormal quantity of computing resources and possibly becoming temporarily unavailable for its users.
No analysis available yet.
Remediation
Vendor Solution
Update Mattermost Server to versions 7.8.10, 8.0.2, 8.1.1 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2399 | Mattermost fails to enforce character limits in all possible notification props allowing an attacker to send a really long value for a notification_prop resulting in the server consuming an abnormal quantity of computing resources and possibly becoming temporarily unavailable for its users. |
Github GHSA |
GHSA-33r7-wjfc-7w98 | Mattermost Uncontrolled Resource Consumption vulnerability |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
Fri, 20 Sep 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-09-20T16:02:00.219Z
Reserved: 2023-09-26T09:37:55.255Z
Link: CVE-2023-5196
Updated: 2024-08-02T07:52:07.819Z
Status : Modified
Published: 2023-09-29T10:15:10.890
Modified: 2024-11-21T08:41:16.843
Link: CVE-2023-5196
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA