CVE-2022-1333: A specifically drafted Playbook could trigger large amount of webhook requests leading to Denial of Service
Mattermost Playbooks plugin v1.24.0 and earlier fails to properly check the limit on the number of webhooks, which allows authenticated and authorized users to create a specifically drafted Playbook which could trigger a large amount of webhook requests leading to Denial of Service.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-1333?
CVE-2022-1333 is a vulnerability that can lead to Denial of Service due to improper handling of webhook limits.
How do I fix CVE-2022-1333?
To fix CVE-2022-1333, upgrade the Mattermost Playbooks plugin to version 1.24.1 or later.
Who is affected by CVE-2022-1333?
CVE-2022-1333 affects users of Mattermost Playbooks plugin version 1.24.0 and earlier.
What kind of attack does CVE-2022-1333 enable?
CVE-2022-1333 allows attackers to create Playbooks that trigger a large number of webhook requests, leading to service interruptions.
Is CVE-2022-1333 a remote or local vulnerability?
CVE-2022-1333 is a local vulnerability that requires authenticated and authorized users to exploit.