Описание
Mattermost denial of service through long emoji value
Mattermost fails to properly validate the length of the emoji value in the custom user status, allowing an attacker to send multiple times a very long string as an emoji value causing high resource consumption and possibly crashing the server.
Пакеты
github.com/mattermost/mattermost/server/v8
>= 9.3.0, < 9.3.1
9.3.1
github.com/mattermost/mattermost/server/v8
>= 9.2.0, < 9.2.5
9.2.5
Связанные уязвимости
Mattermost fails to properly validate the length of the emoji value in the custom user status, allowing an attacker to send multiple times a very long string as an emoji value causing high resource consumption and possibly crashing the server.
Mattermost fails to properly validate the length of the emoji value in ...
Уязвимость приложения для обмена мгновенными сообщениями Mattermost, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании