Mattermost fails to enforce character limits in all possible notification props allowing an attacker to send a really long value for a notification_prop resulting in the server consuming an abnormal quantity of computing resources and possibly becoming temporarily unavailable for its users.
2023-09-29T10:15:10.890
2024-11-21T08:41:16.843
Modified
CVSSv3.1: 6.5 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mattermost | mattermost | < 7.8.10 | Yes |
Application | mattermost | mattermost | < 8.0.2 | Yes |
Application | mattermost | mattermost | < 8.1.1 | Yes |