VYPR
Moderate severityNVD Advisory· Published Nov 23, 2022· Updated Dec 6, 2024

Authenticated user could send multiple requests containing a parameter which could fetch a large amount of data and can crash a Mattermost server

CVE-2022-4045

Description

A denial-of-service vulnerability in the Mattermost allows an authenticated user to crash the server via multiple requests to one of the API endpoints which could fetch a large amount of data.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/mattermost/mattermost-serverGo
< 7.1.47.1.4
github.com/mattermost/mattermost-serverGo
>= 7.2.0, < 7.2.17.2.1
github.com/mattermost/mattermost-serverGo
>= 7.3.0, < 7.3.17.3.1

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.