MEDIUM · 4.3

CVE-2023-48369

Mattermost fails to limit the log size of server logs allowing an attacker sending specially crafted requests to different endpoints to potentially overflow the log.

Vulnerability Description

Mattermost fails to limit the log size of server logs allowing an attacker sending specially crafted requests to different endpoints to potentially overflow the log.

CVSS Score

4.3

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
LOW

Affected Products

VendorProductVersions
MattermostMattermost<= 7.8.12

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-48369?

CVE-2023-48369 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Mattermost fails to limit the log size of server logs allowing an attacker sending specially crafted requests to different endpoints to potentially overflow the log.

How severe is CVE-2023-48369?

CVE-2023-48369 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-48369?

Check the references section above for vendor advisories and patch information. Affected products include: Mattermost Mattermost.