← Back

CVE-2023-48268

nvd nist
Published: Nov 27, 2023Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

Mattermost fails to limit the amount of data extracted from compressed archives during board import in Mattermost Boards allowing an attacker to consume excessive resources, possibly leading to Denial of Service, by importing a board using a specially crafted zip (zip bomb).

Affected (4)

1 product
Mattermost
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Mattermost
Up to 7.8.12
From 8.0.0 to 8.1.3
From 9.0.0 to 9.0.1
Version 9.1.0

References (2)

Source: responsibledisclosure@mattermost.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.