DoS via Channel Notification Properties
Published Sep 29, 2023
6.5
MEDIUMCVSS 3.1
EPSS 0.68%
Description
Mattermost fails to enforce character limits in all possible notification props allowing an attacker to send a really long value for a notification_prop resulting in the server consuming an abnormal quantity of computing resources and possibly becoming temporarily unavailable for its users.
Affected products
-
Affected
- ≥ 0, ≤ 7.8.9
- ≥ 0, ≤ 8.0.1
- 8.1.0
Unaffected
- 7.8.10
- 8.0.2
- 8.1.1
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Mattermost | Mattermost | unaffected | Affected
Unaffected
|
- ≥ 7.0.0 · < 7.8.10
- ≥ 8.0.0 · < 8.0.2
- ≥ 8.1.0 · < 8.1.1
No data.
No Red Hat product state for this CVE.
github.com/mattermost/mattermost-server/v6
Go
Introduced 0 Fixed 7.8.10github.com/mattermost/mattermost/server/v8
Go
Introduced 8.1.0 Fixed 8.1.1github.com/mattermost/mattermost/server/v8
Go
Introduced 8.0.0 Fixed 8.0.2
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/mattermost/mattermost-server/v6 | 0 | 7.8.10 |
| Go | github.com/mattermost/mattermost/server/v8 | 8.1.0 | 8.1.1 |
| Go | github.com/mattermost/mattermost/server/v8 | 8.0.0 | 8.0.2 |
Remediation
Vendor solution
Update Mattermost Server to versions 7.8.10, 8.0.2, 8.1.1 or higher.
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-2399 Advisory
- https://github.com/advisories/GHSA-33r7-wjfc-7w98 Advisory
- https://mattermost.com/security-updates Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-5196
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-2399 | Advisory | |
| https://github.com/advisories/GHSA-33r7-wjfc-7w98 | Advisory | |
| https://mattermost.com/security-updates | Vendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2023-5196 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub