CVE-2023-48268
27.11.2023, 10:15
Mattermost fails tolimit the amount of data extracted from compressed archives during board import in Mattermost Boardsallowing an attacker to consume excessive resources, possibly leading to Denial of Service, byimporting a board using a specially crafted zip (zip bomb).Enginsight
Vendor | Product | Version |
---|---|---|
mattermost | mattermost | 𝑥 ≤ 7.8.12 |
mattermost | mattermost | 8.0.0 ≤ 𝑥 ≤ 8.1.3 |
mattermost | mattermost | 9.0.0 ≤ 𝑥 ≤ 9.0.1 |
mattermost | mattermost | 9.1.0 |
𝑥
= Vulnerable software versions