Description
Mattermost Server versions 9.5.x before 9.5.2, 9.4.x before 9.4.4, 9.3.x before 9.3.3, 8.1.x before 8.1.11 don't limit the number of user preferences which allows an attacker to send a large number of user preferences potentially causing denial of service.
No analysis available yet.
Remediation
Vendor Solution
Update Mattermost Server to versions 9.6.0, 9.5.2, 9.4.4, 9.3.3, 8.1.11 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-1247 | Mattermost Server versions 9.5.x before 9.5.2, 9.4.x before 9.4.4, 9.3.x before 9.3.3, 8.1.x before 8.1.11 don't limit the number of user preferences which allows an attacker to send a large number of user preferences potentially causing denial of service. |
Github GHSA |
GHSA-mcw6-3256-64gg | Mattermost Server doesn't limit the number of user preferences |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
Thu, 12 Dec 2024 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost
Mattermost mattermost Server |
|
| Weaknesses | CWE-770 | |
| CPEs | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mattermost
Mattermost mattermost Server |
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-09-03T18:35:47.389Z
Reserved: 2024-04-03T10:03:48.285Z
Link: CVE-2024-28949
Updated: 2024-08-02T01:03:51.100Z
Status : Analyzed
Published: 2024-04-05T09:15:09.497
Modified: 2024-12-12T21:38:08.237
Link: CVE-2024-28949
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA