Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w28r-7qw2-ghqc

Опубликовано: 09 окт. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

Mattermost fails to deduplicate input IDs allowing a simple user to cause the application to consume excessive resources and possibly crash by sending a specially crafted request to /api/v4/users/ids with multiple identical IDs.

Mattermost fails to deduplicate input IDs allowing a simple user to cause the application to consume excessive resources and possibly crash by sending a specially crafted request to /api/v4/users/ids with multiple identical IDs.

EPSS

Процентиль: 31%
0.00118
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 4.3
nvd
больше 2 лет назад

Mattermost fails to deduplicate input IDs allowing a simple user to cause the application to consume excessive resources and possibly crash by sending a specially crafted request to /api/v4/users/ids with multiple identical IDs.

CVSS3: 4.3
debian
больше 2 лет назад

Mattermost fails to deduplicate input IDs allowing asimple user to cau ...

EPSS

Процентиль: 31%
0.00118
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-400