CVE-2023-40703

MEDIUM4.3EPSS 0.09%

Mattermost Uncontrolled Resource Consumption vulnerability

Published: 11/27/2023Modified: 2/4/2026
Also known as:GHSA-c37r-v8jx-7cv2CGA-rf23-3r6f-fwww

Description

Mattermost fails to properly limit the characters allowed in different fields of a block in Mattermost Boards allowing a attacker to consume excessive resources, possibly leading to Denial of Service, by patching the field of a block using a specially crafted string. 

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM4.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

References (3)