A call stack overflow bug in the SAML login feature in Mattermost server in versions up to and including 6.3.2 allows an attacker to crash the server via submitting a maliciously crafted POST body.
2022-03-10T17:45:00.063
2024-11-21T06:39:38.197
Modified
CVSSv3.1: 5.3 (MEDIUM)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mattermost | mattermost_server | < 5.37.8 | Yes |
Application | mattermost | mattermost_server | < 6.1.3 | Yes |
Application | mattermost | mattermost_server | < 6.2.3 | Yes |
Application | mattermost | mattermost_server | < 6.3.3 | Yes |