Description
Mattermost fails to deduplicate input IDs allowing a simple user to cause the application to consume excessive resources and possibly crash by sending a specially crafted request to /api/v4/users/ids with multiple identical IDs.
No analysis available yet.
Remediation
Vendor Solution
Update Mattermost Server to versions 7.8.11, 8.0.3, 8.1.2 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-57650 | Mattermost fails to deduplicate input IDs allowing a simple user to cause the application to consume excessive resources and possibly crash by sending a specially crafted request to /api/v4/users/ids with multiple identical IDs. |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
No history.
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-09-05T19:46:32.169Z
Reserved: 2023-10-02T12:25:25.552Z
Link: CVE-2023-5333
Updated: 2024-08-02T07:52:08.633Z
Status : Modified
Published: 2023-10-09T11:15:11.363
Modified: 2024-11-21T08:41:33.157
Link: CVE-2023-5333
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD