← back
CVE-2022-1333lowCWE-770

A specifically drafted Playbook could trigger large amount of webhook requests leading to Denial of Service

8Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 3.5epss 0.7%
exploitation probability
0.7%top 47% of all CVEs
observed exploitation
nono source reports it
Mattermost Playbooks plugin v1.24.0 and earlier fails to properly check the limit on the number of webhooks, which allows authenticated and authorized users to create a specifically drafted Playbook which could trigger a large amount of webhook requests leading to Denial of Service.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L