Lucene search

K
cve[email protected]CVE-2023-5969
HistoryNov 06, 2023 - 4:15 p.m.

CVE-2023-5969

2023-11-0616:15:42
CWE-400
web.nvd.nist.gov
31
mattermost
api
security
vulnerability
cve-2023-5969
request sanitization
memory caching

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

5.1 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

17.0%

Mattermost fails to properly sanitize the request toย /api/v4/redirect_location allowing anย attacker,ย sending a specially crafted request to /api/v4/redirect_location,ย to fill up the memory due to caching large items.

Affected configurations

NVD
Node
mattermostmattermostRangeโ‰ค7.8.11
OR
mattermostmattermostRange8.0.0โ€“8.0.3
OR
mattermostmattermostRange8.1.0โ€“8.1.2
OR
mattermostmattermostMatch9.0.0

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Mattermost",
    "vendor": "Mattermost",
    "versions": [
      {
        "lessThanOrEqual": "7.8.11",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      },
      {
        "lessThanOrEqual": "8.0.3",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      },
      {
        "lessThanOrEqual": "8.1.2",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      },
      {
        "lessThanOrEqual": "9.0.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      },
      {
        "status": "unaffected",
        "version": "7.8.12"
      },
      {
        "status": "unaffected",
        "version": "8.0.4"
      },
      {
        "status": "unaffected",
        "version": "8.1.3"
      },
      {
        "status": "unaffected",
        "version": "9.0.1"
      }
    ]
  }
]

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

5.1 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

17.0%