Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-32h7-7j94-8fc2

Опубликовано: 09 фев. 2024
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Mattermost vulnerable to denial of service via large number of emoji reactions

Mattermost fails to check if a custom emoji reaction exists when sending it to a post and to limit the amount of custom emojis allowed to be added in a post, allowing an attacker sending a huge amount of non-existent custom emojis in a post to crash the mobile app of a user seeing the post. Fetching posts with huge amounts of reactions results in Uncontrolled Resource Consumption.

Пакеты

Наименование

github.com/mattermost/mattermost/server/v8

go
Затронутые версииВерсия исправления

< 8.1.8

8.1.8

Наименование

github.com/mattermost/mattermost/server/v8

go
Затронутые версииВерсия исправления

>= 9.2.0, < 9.2.4

9.2.4

Наименование

github.com/mattermost/mattermost/server/v8

go
Затронутые версииВерсия исправления

>= 9.1.0, < 9.1.5

9.1.5

EPSS

Процентиль: 56%
0.00336
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 4.3
nvd
почти 2 года назад

Mattermost fails to check if a custom emoji reaction exists when sending it to a post and to limit the amount of custom emojis allowed to be added in a post, allowing an attacker sending a huge amount of non-existent custom emojis in a post to crash the mobile app of a user seeing the post and to crash the server due to overloading when clients attempt to retrive the aforementioned post. 

CVSS3: 4.3
debian
почти 2 года назад

Mattermost fails to check if a custom emoji reaction exists when sendi ...

EPSS

Процентиль: 56%
0.00336
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-400