Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-48268


Mattermost fails to limit the amount of data extracted from compressed archives during board import in Mattermost Boards allowing an attacker to consume excessive resources, possibly leading to Denial of Service, by importing a board using a specially crafted zip (zip bomb).


Published

2023-11-27T10:15:08.217

Last Modified

2024-11-21T08:31:22.667

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-400
  • Type: Primary
    CWE-400

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application mattermost mattermost ≤ 7.8.12 Yes
Application mattermost mattermost ≤ 8.1.3 Yes
Application mattermost mattermost ≤ 9.0.1 Yes
Application mattermost mattermost 9.1.0 Yes

References