A call stack overflow bug in the SAML login feature in Mattermost server in versions up to and including 6.3.2 allows an attacker to crash the server via submitting a maliciously crafted POST body.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-15935 | A call stack overflow bug in the SAML login feature in Mattermost server in versions up to and including 6.3.2 allows an attacker to crash the server via submitting a maliciously crafted POST body. |
Fixes
Solution
Update the Mattermost version to v6.3.3, 6.2.3, 6.1.3, or 5.37.8, depending on the minor version being run
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates/ |
|
History
Sat, 07 Dec 2024 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-12-06T23:10:52.487Z
Reserved: 2022-03-09T00:00:00
Link: CVE-2022-0903
Updated: 2024-08-02T23:47:42.124Z
Status : Modified
Published: 2022-03-10T17:45:00.063
Modified: 2024-11-21T06:39:38.197
Link: CVE-2022-0903
No data.
OpenCVE Enrichment
No data.
EUVD