CVE-2023-2785

Mattermost fails to properly truncate the postgres error log message of a search query failure allowing an attacker to cause the creation oflarge log fileswhich can result in Denial of Service

ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
MattermostCNA
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 31%
VendorProductVersion
mattermostmattermost
7.1.0 ≤
𝑥
≤ 7.1.9
mattermostmattermost
7.8.0 ≤
𝑥
≤ 7.8.4
mattermostmattermost
7.9.0 ≤
𝑥
≤ 7.9.3
mattermostmattermost
7.10.0
𝑥
= Vulnerable software versions