Description
Mattermost fails to properly sanitize the request to /api/v4/redirect_location allowing an attacker, sending a specially crafted request to /api/v4/redirect_location, to fill up the memory due to caching large items.
No analysis available yet.
Remediation
Vendor Solution
Update Mattermost Server to versions 7.8.12, 8.0.4, 8.1.3, 9.0.1 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-3048 | Mattermost fails to properly sanitize the request to /api/v4/redirect_location allowing an attacker, sending a specially crafted request to /api/v4/redirect_location, to fill up the memory due to caching large items. |
Github GHSA |
GHSA-w496-f5qq-m58j | Mattermost vulnerable to excessive memory consumption |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
No history.
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-09-17T13:07:28.847Z
Reserved: 2023-11-06T15:45:39.602Z
Link: CVE-2023-5969
Updated: 2024-08-02T08:14:25.131Z
Status : Modified
Published: 2023-11-06T16:15:42.987
Modified: 2024-11-21T08:42:53.270
Link: CVE-2023-5969
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA