PT-2024-22239 · Mattermost · Mattermost Server

Published

2024-03-15

·

Updated

2024-12-19

·

CVE-2024-28053

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Mattermost Server versions 8.1.x before 8.1.10
Description The issue is related to resource exhaustion, where the server fails to limit the size of the payload that can be read and parsed, allowing an attacker to send a very large email payload and crash the server.
Recommendations For Mattermost Server versions 8.1.x before 8.1.10, update to version 8.1.10 or later to resolve the issue.

Fix

DoS

Resource Exhaustion

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

BIT-MATTERMOST-2024-28053
CVE-2024-28053
GHSA-QQC8-RV37-79Q5
GO-2024-3334
OPENSUSE-SU-2024:14603-1

Affected Products

Mattermost Server