CVE-2023-2785: Specially crafted search query can cause large log entries in postgres
Mattermost fails to properly truncate the postgres error log message of a search query failure allowing an attacker to cause the creation of large log files which can result in Denial of Service
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-2785?
CVE-2023-2785 is a vulnerability in Mattermost that allows an attacker to cause the creation of large log files and result in Denial of Service.
What is the severity of CVE-2023-2785?
The severity of CVE-2023-2785 is medium.
How does CVE-2023-2785 affect Mattermost?
CVE-2023-2785 affects Mattermost versions between 7.1.0 and 7.9.3, and version 7.10.0. It fails to properly truncate the postgres error log message of a search query failure.
How can an attacker exploit CVE-2023-2785?
An attacker can exploit CVE-2023-2785 by causing the creation of large log files, leading to a Denial of Service.
How can I fix CVE-2023-2785?
To fix CVE-2023-2785, it is recommended to update Mattermost to a version that is not affected by this vulnerability. Please refer to the Mattermost security updates for more information.