Mattermost fails to enforce a limit for the size of the cache entry for OpenGraph data allowing an attacker to send a specially crafted request to the /api/v4/opengraph filling the cache and turning the server unavailable.
References
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published: 2023-10-09T10:38:39.415Z

Updated: 2024-09-05T19:47:56.144Z

Reserved: 2023-10-02T10:48:43.542Z

Link: CVE-2023-5330

cve-icon Vulnrichment

Updated: 2024-08-02T07:52:08.656Z

cve-icon NVD

Status : Analyzed

Published: 2023-10-09T11:15:11.197

Modified: 2023-10-12T18:31:55.587

Link: CVE-2023-5330

cve-icon Redhat

No data.