CVE-2023-5330: Denial of Service via Opengraph Data Cache
Mattermost fails to enforce a limit for the size of the cache entry for OpenGraph data allowing an attacker to send a specially crafted request to the /api/v4/opengraph filling the cache and turning the server unavailable.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this Mattermost vulnerability?
The vulnerability ID for this Mattermost vulnerability is CVE-2023-5330.
What is the title of this Mattermost vulnerability?
The title of this Mattermost vulnerability is "Mattermost fails to enforce a limit for the size of the cache entry for OpenGraph data allowing an attacker to turn the server unavailable."
What is the severity rating of the vulnerability CVE-2023-5330?
The severity rating of the vulnerability CVE-2023-5330 is high.
Which versions of Mattermost Server are affected by this vulnerability?
Mattermost Server versions 7.8.11, 8.0.0 to 8.0.3, and 8.1.0 to 8.1.2 are affected by this vulnerability.
How can an attacker exploit the vulnerability CVE-2023-5330?
An attacker can exploit the vulnerability CVE-2023-5330 by sending a specially crafted request to the /api/v4/opengraph endpoint, filling the cache and turning the server unavailable.