CVE-2023-5333: Denial of Service via multiple identical User IDs in /api/v4/users/ids
Mattermost fails to deduplicate input IDs allowing a simple user to cause the application to consume excessive resources and possibly crash by sending a specially crafted request to /api/v4/users/ids with multiple identical IDs.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-5333?
CVE-2023-5333 is a vulnerability in Mattermost that allows a simple user to cause the application to consume excessive resources and possibly crash.
How does Mattermost fail to deduplicate input IDs?
Mattermost fails to deduplicate input IDs when a user sends a specially crafted request to /api/v4/users/ids with multiple identical IDs.
What versions of Mattermost are affected by CVE-2023-5333?
Mattermost versions up to 7.8.11, 8.0.0 to 8.0.3, and 8.1.0 to 8.1.2 are affected by CVE-2023-5333.
What is the severity of CVE-2023-5333?
CVE-2023-5333 has a severity rating of medium (6.5).
How can I fix CVE-2023-5333?
To fix CVE-2023-5333, update your Mattermost server to a version that is not affected by the vulnerability.