Description
Resource Exhaustion in Mattermost Server versions 8.1.x before 8.1.10 fails to limit the size of the payload that can be read and parsed allowing an attacker to send a very large email payload and crash the server.

Published: 2024-03-15
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Update Mattermost Server to versions 9.5.0, 8.1.10 or higher.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-1049 Resource Exhaustion in Mattermost Server versions 8.1.x before 8.1.10 fails to limit the size of the payload that can be read and parsed allowing an attacker to send a very large email payload and crash the server.
Github GHSA Github GHSA GHSA-qqc8-rv37-79q5 Mattermost Server Resource Exhaustion
References
History

Fri, 13 Dec 2024 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost Server
Weaknesses CWE-770
CPEs cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
Vendors & Products Mattermost
Mattermost mattermost Server

Subscriptions

Mattermost Mattermost Server
cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2024-08-12T13:40:25.079Z

Reserved: 2024-03-14T09:38:07.478Z

Link: CVE-2024-28053

cve-icon Vulnrichment

Updated: 2024-08-02T00:48:47.805Z

cve-icon NVD

Status : Analyzed

Published: 2024-03-15T09:15:07.293

Modified: 2024-12-13T17:04:25.663

Link: CVE-2024-28053

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses