Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p2wq-4ggp-45f3

Опубликовано: 26 апр. 2024
Источник: github
Github: Прошло ревью
CVSS3: 3.1

Описание

Mattermost fails to limit the size of a request path

Mattermost versions 8.1.x <= 8.1.10, 9.6.x <= 9.6.0, 9.5.x <= 9.5.2 and 8.1.x <= 8.1.11 fail to limit the size of a request path that includes user inputs which allows an attacker to cause excessive resource consumption, possibly leading to a DoS via sending large request paths

Пакеты

Наименование

github.com/mattermost/mattermost-server

go
Затронутые версииВерсия исправления

>= 8.1.0, <= 8.1.11

8.1.12

Наименование

github.com/mattermost/mattermost-server

go
Затронутые версииВерсия исправления

>= 9.5.0, <= 9.5.2

9.5.3

Наименование

github.com/mattermost/mattermost-server

go
Затронутые версииВерсия исправления

>= 9.6.0-rc1, <= 9.6.0

9.6.1

EPSS

Процентиль: 34%
0.00138
Низкий

3.1 Low

CVSS3

Дефекты

CWE-400
CWE-770

Связанные уязвимости

CVSS3: 3.1
redhat
почти 2 года назад

Mattermost versions 8.1.x <= 8.1.10, 9.6.x <= 9.6.0, 9.5.x <= 9.5.2 and 8.1.x <= 8.1.11 fail to limit the size of a request path that includes user inputs which allows an attacker to cause excessive resource consumption, possibly leading to a DoS via sending large request paths

CVSS3: 3.1
nvd
почти 2 года назад

Mattermost versions 8.1.x <= 8.1.10, 9.6.x <= 9.6.0, 9.5.x <= 9.5.2 and 8.1.x <= 8.1.11 fail to limit the size of a request path that includes user inputs which allows an attacker to cause excessive resource consumption, possibly leading to a DoS via sending large request paths

CVSS3: 3.1
debian
почти 2 года назад

Mattermost versions 8.1.x <= 8.1.10, 9.6.x <= 9.6.0, 9.5.x <= 9.5.2 an ...

EPSS

Процентиль: 34%
0.00138
Низкий

3.1 Low

CVSS3

Дефекты

CWE-400
CWE-770