Moderate severityNVD Advisory· Published Nov 27, 2023· Updated Dec 2, 2024
Denial of Service via Board Import Zip Bomb
CVE-2023-48268
Description
Mattermost fails to limit the amount of data extracted from compressed archives during board import in Mattermost Boards allowing an attacker to consume excessive resources, possibly leading to Denial of Service, by importing a board using a specially crafted zip (zip bomb).
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/mattermost/mattermost/server/v8Go | >= 9.1.0, < 9.1.1 | 9.1.1 |
github.com/mattermost/mattermost/server/v8Go | >= 9.0.0, < 9.0.2 | 9.0.2 |
github.com/mattermost/mattermost/server/v8Go | < 8.1.4 | 8.1.4 |
github.com/mattermost/mattermost-server/v6Go | < 7.8.13 | 7.8.13 |
Affected products
1- Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/advisories/GHSA-j4c3-3h73-74m9ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-48268ghsaADVISORY
- mattermost.com/security-updatesghsaWEB
News mentions
0No linked articles in our index yet.