Mattermost fails to limit the amount of data extracted from compressed archives during board import in Mattermost Boards allowing an attacker to consume excessive resources, possibly leading to Denial of Service, by importing a board using a specially crafted zip (zip bomb).
References
Link Resource
https://mattermost.com/security-updates Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: Mattermost

Published: 2023-11-27T09:07:29.918Z

Updated: 2023-11-27T09:07:29.918Z

Reserved: 2023-11-22T11:18:57.625Z


Link: CVE-2023-48268

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-11-27T10:15:08.217

Modified: 2023-12-01T21:30:14.497


Link: CVE-2023-48268

JSON object: View

cve-icon Redhat Information

No data.

CWE