VYPR
Low severityNVD Advisory· Published Mar 15, 2024· Updated Aug 12, 2024

Resource Exhaustion via the Invitation Feature

CVE-2024-28053

Description

Resource Exhaustion in Mattermost Server versions 8.1.x before 8.1.10 fails to limit the size of the payload that can be read and parsed allowing an attacker to send a very large email payload and crash the server.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/mattermost/mattermost/server/v8Go
< 0.0.0-20240209181221-674f549daf0e0.0.0-20240209181221-674f549daf0e
github.com/mattermost/mattermost-serverGo
< 0.0.0-20240209181221-674f549daf0e0.0.0-20240209181221-674f549daf0e
github.com/mattermost/mattermost-server/v5Go
< 0.0.0-20240209181221-674f549daf0e0.0.0-20240209181221-674f549daf0e
github.com/mattermost/mattermost-server/v6Go
< 0.0.0-20240209181221-674f549daf0e0.0.0-20240209181221-674f549daf0e

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.