Vulnerability Details CVE-2023-5196
Mattermost fails to enforce character limits in all possible notification props allowing an attacker to send a really long value for a notification_prop resulting in the server consuming an abnormal quantity of computing resources and possibly becoming temporarily unavailable for its users.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 38.4%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2023-5196
-
cpe:2.3:a:mattermost:mattermost:7.0.0
-
cpe:2.3:a:mattermost:mattermost:7.0.1
-
cpe:2.3:a:mattermost:mattermost:7.0.2
-
cpe:2.3:a:mattermost:mattermost:7.1.0
-
cpe:2.3:a:mattermost:mattermost:7.1.1
-
cpe:2.3:a:mattermost:mattermost:7.1.2
-
cpe:2.3:a:mattermost:mattermost:7.1.3
-
cpe:2.3:a:mattermost:mattermost:7.1.4
-
cpe:2.3:a:mattermost:mattermost:7.1.5
-
cpe:2.3:a:mattermost:mattermost:7.1.6
-
cpe:2.3:a:mattermost:mattermost:7.1.7
-
cpe:2.3:a:mattermost:mattermost:7.1.8
-
cpe:2.3:a:mattermost:mattermost:7.1.9
-
cpe:2.3:a:mattermost:mattermost:7.2.0
-
cpe:2.3:a:mattermost:mattermost:7.2.1
-
cpe:2.3:a:mattermost:mattermost:7.3.0
-
cpe:2.3:a:mattermost:mattermost:7.3.1
-
cpe:2.3:a:mattermost:mattermost:7.4.0
-
cpe:2.3:a:mattermost:mattermost:7.4.1
-
cpe:2.3:a:mattermost:mattermost:7.5.0
-
cpe:2.3:a:mattermost:mattermost:7.5.1
-
cpe:2.3:a:mattermost:mattermost:7.5.2
-
cpe:2.3:a:mattermost:mattermost:7.7.0
-
cpe:2.3:a:mattermost:mattermost:7.7.1
-
cpe:2.3:a:mattermost:mattermost:7.7.2
-
cpe:2.3:a:mattermost:mattermost:7.7.3
-
cpe:2.3:a:mattermost:mattermost:7.7.4
-
cpe:2.3:a:mattermost:mattermost:7.8.0
-
cpe:2.3:a:mattermost:mattermost:7.8.1
-
cpe:2.3:a:mattermost:mattermost:7.8.2
-
cpe:2.3:a:mattermost:mattermost:7.8.3
-
cpe:2.3:a:mattermost:mattermost:7.8.4
-
cpe:2.3:a:mattermost:mattermost:7.8.5
-
cpe:2.3:a:mattermost:mattermost:7.8.6
-
cpe:2.3:a:mattermost:mattermost:7.8.7
-
cpe:2.3:a:mattermost:mattermost:7.8.8
-
cpe:2.3:a:mattermost:mattermost:7.8.9
-
cpe:2.3:a:mattermost:mattermost:8.0.0
-
cpe:2.3:a:mattermost:mattermost:8.0.1
-
cpe:2.3:a:mattermost:mattermost:8.1.0