First published: Fri Jun 16 2023(Updated: )
Mattermost fails to properly truncate the postgres error log message of a search query failure allowing an attacker to cause the creation of large log files which can result in Denial of Service
Credit: responsibledisclosure@mattermost.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mattermost Mattermost | >=7.1.0<=7.1.9 | |
Mattermost Mattermost | >=7.8.0<=7.8.4 | |
Mattermost Mattermost | >=7.9.0<=7.9.3 | |
Mattermost Mattermost | =7.10.0 |
Update Mattermost Server to versions v7.1.10, v7.8.5, v7.9.4, v.7.10.1 or higher.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-2785 is a vulnerability in Mattermost that allows an attacker to cause the creation of large log files and result in Denial of Service.
The severity of CVE-2023-2785 is medium.
CVE-2023-2785 affects Mattermost versions between 7.1.0 and 7.9.3, and version 7.10.0. It fails to properly truncate the postgres error log message of a search query failure.
An attacker can exploit CVE-2023-2785 by causing the creation of large log files, leading to a Denial of Service.
To fix CVE-2023-2785, it is recommended to update Mattermost to a version that is not affected by this vulnerability. Please refer to the Mattermost security updates for more information.