Описание
Mattermost Server doesn't limit the number of user preferences
Mattermost Server versions 9.5.x before 9.5.2, 9.4.x before 9.4.4, 9.3.x before 9.3.3, 8.1.x before 8.1.11 don't limit the number of user preferences which allows an attacker to send a large number of user preferences potentially causing denial of service.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2024-28949
- https://github.com/mattermost/mattermost/commit/11a21f4da352a472a09de3b8e125514750a6619a
- https://github.com/mattermost/mattermost/commit/362b7d29d35c00fe80721d3d47442a4f3168eb2b
- https://github.com/mattermost/mattermost/commit/5632d6b4ff6d019a21bb8ddd037d4a931cd85ae2
- https://github.com/mattermost/mattermost/commit/88f9285173dc4cb35fa19a8b8604e098a567f704
- https://mattermost.com/security-updates
- https://pkg.go.dev/vuln/GO-2024-2695
Пакеты
github.com/mattermost/mattermost/server/v8
>= 8.1.0, < 8.1.11
8.1.11
github.com/mattermost/mattermost/server/v8
>= 9.3.0, < 9.3.3
9.3.3
github.com/mattermost/mattermost/server/v8
>= 9.4.0, < 9.4.4
9.4.4
github.com/mattermost/mattermost/server/v8
>= 9.5.0, < 9.5.2
9.5.2
EPSS
5.3 Medium
CVSS4
4.3 Medium
CVSS3
CVE ID
Дефекты
Связанные уязвимости
Mattermost Server versions 9.5.x before 9.5.2, 9.4.x before 9.4.4, 9.3.x before 9.3.3, 8.1.x before 8.1.11 don't limit the number of user preferences which allows an attacker to send a large number of user preferences potentially causing denial of service.
Mattermost Server versions 9.5.x before 9.5.2, 9.4.x before 9.4.4, 9.3 ...
EPSS
5.3 Medium
CVSS4
4.3 Medium
CVSS3