CVE-2023-40703: Denial of Service via specially crafted block fields in Mattermost Boards
Mattermost fails to properly limit the characters allowed in different fields of a block in Mattermost Boards allowing a attacker to consume excessive resources, possibly leading to Denial of Service, by patching the field of a block using a specially crafted string.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-40703?
CVE-2023-40703 is a vulnerability in Mattermost Boards that allows an attacker to consume excessive resources, possibly leading to a Denial of Service, by patching the field of a block using a specially crafted string.
How does CVE-2023-40703 affect Mattermost?
CVE-2023-40703 affects Mattermost versions 7.8.13 up to 9.1.1.
What is the severity of CVE-2023-40703?
CVE-2023-40703 has a severity rating of 4.3, which is considered medium.
How can I fix CVE-2023-40703?
To fix CVE-2023-40703, it is recommended to update to Mattermost versions 7.8.14, 8.1.5, 9.0.3, or 9.1.2.
Where can I find more information about CVE-2023-40703?
You can find more information about CVE-2023-40703 on the Mattermost website, NIST vulnerability database, and GitHub advisory.