CVE-2023-48268: Denial of Service via Board Import Zip Bomb
Mattermost fails to limit the amount of data extracted from compressed archives during board import in Mattermost Boards allowing an attacker to consume excessive resources, possibly leading to Denial of Service, by importing a board using a specially crafted zip (zip bomb).
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-48268?
CVE-2023-48268 is a vulnerability in Mattermost that allows an attacker to consume excessive resources, possibly leading to Denial of Service, by importing a specially crafted zip bomb during board import in Mattermost Boards.
How does the Denial of Service via Board Import Zip Bomb vulnerability work?
The vulnerability occurs because Mattermost fails to limit the amount of data extracted from compressed archives during board import, allowing an attacker to consume excessive resources by importing a specially crafted zip bomb.
What is the severity of CVE-2023-48268?
CVE-2023-48268 has a severity level of medium with a CVSS score of 4.3.
Which versions of Mattermost are affected by CVE-2023-48268?
Mattermost versions 7.8.13, 8.1.4, 9.0.0 to 9.0.2, and 9.1.0 to 9.1.1 are affected by CVE-2023-48268.
How can I fix CVE-2023-48268?
To fix CVE-2023-48268, update your Mattermost installation to version 7.8.13, 8.1.4, 9.0.2, or 9.1.1.