CVE-2022-0903
published 2022-03-10CVE-2022-0903: A call stack overflow bug in the SAML login feature in Mattermost server in versions up to and including 6.3.2 allows an attacker to crash the server via…
high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
A call stack overflow bug in the SAML login feature in Mattermost server in versions up to and including 6.3.2 allows an attacker to crash the server via submitting a maliciously crafted POST body.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mattermost | mattermost | >= 5.37 < 5.37.8 | 5.37.8 |
| mattermost | mattermost | >= 6.1 < 6.1.3 | 6.1.3 |
| mattermost | mattermost | >= 6.2 < 6.2.3 | 6.2.3 |
| mattermost | mattermost | >= 6.3 < 6.3.3 | 6.3.3 |
| mattermost | mattermost_server | < 5.37.8 | 5.37.8 |
| mattermost | mattermost_server | >= 6.0.0 < 6.1.3 | 6.1.3 |
| mattermost | mattermost_server | >= 6.2.0 < 6.2.3 | 6.2.3 |
| mattermost | mattermost_server | >= 6.3.0 < 6.3.3 | 6.3.3 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
cisa8.8HIGH