Specially crafted search query can cause large log entries in postgres
Vulnerability Description
Mattermost fails to properly truncate the postgres error log message of a search query failure allowing an attacker to cause the creation of large log files which can result in Denial of Service
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-2785
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Filip Omazić
References
More from Mattermost
View All →Affected Vendor
Mattermost
View all reports →