PT-2024-32617 · Mattermost+1 · Mattermost+1

Doyensec

·

Published

2024-10-29

·

Updated

2024-11-08

·

CVE-2024-47401

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Mattermost versions 9.5.x through 9.5.9 Mattermost versions 9.10.x through 9.10.2 Mattermost versions 9.11.x through 9.11.1
Description The issue allows an attacker to generate a large response and cause an amplified GraphQL response which could cause the application to crash by sending a specially crafted request to Playbooks. This is due to the failure to prevent detailed error messages from being displayed in Playbooks.
Recommendations For Mattermost versions 9.5.x through 9.5.9, update to a version later than 9.5.9 to resolve the issue. For Mattermost versions 9.10.x through 9.10.2, update to a version later than 9.10.2 to resolve the issue. For Mattermost versions 9.11.x through 9.11.1, update to a version later than 9.11.1 to resolve the issue. As a temporary workaround, consider restricting access to Playbooks to minimize the risk of exploitation.

Fix

DoS

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

CVE-2024-47401
GHSA-762V-RQ7Q-FF97
GO-2024-3234
OPENSUSE-SU-2024:0350-1
OPENSUSE-SU-2024:14458-1
OPENSUSE-SU-2024_3950-1
SUSE-SU-2024:3950-1

Affected Products

Mattermost
Suse