First published: Mon Oct 09 2023(Updated: )
Mattermost fails to deduplicate input IDs allowing a simple user to cause the application to consume excessive resources and possibly crash by sending a specially crafted request to /api/v4/users/ids with multiple identical IDs.
Credit: responsibledisclosure@mattermost.com responsibledisclosure@mattermost.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mattermost Mattermost Server | <7.8.11 | |
Mattermost Mattermost Server | >=8.0.0<8.0.3 | |
Mattermost Mattermost Server | >=8.1.0<8.1.2 | |
<7.8.11 | ||
>=8.0.0<8.0.3 | ||
>=8.1.0<8.1.2 |
Update Mattermost Server to versions 7.8.11, 8.0.3, 8.1.2 or higher.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-5333 is a vulnerability in Mattermost that allows a simple user to cause the application to consume excessive resources and possibly crash.
Mattermost fails to deduplicate input IDs when a user sends a specially crafted request to /api/v4/users/ids with multiple identical IDs.
Mattermost versions up to 7.8.11, 8.0.0 to 8.0.3, and 8.1.0 to 8.1.2 are affected by CVE-2023-5333.
CVE-2023-5333 has a severity rating of medium (6.5).
To fix CVE-2023-5333, update your Mattermost server to a version that is not affected by the vulnerability.