cbcvebase.
CVE-2022-0903
published 2022-03-10

CVE-2022-0903: A call stack overflow bug in the SAML login feature in Mattermost server in versions up to and including 6.3.2 allows an attacker to crash the server via…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
A call stack overflow bug in the SAML login feature in Mattermost server in versions up to and including 6.3.2 allows an attacker to crash the server via submitting a maliciously crafted POST body.

Affected

8 ranges
VendorProductVersion rangeFixed in
mattermostmattermost>= 5.37 < 5.37.85.37.8
mattermostmattermost>= 6.1 < 6.1.36.1.3
mattermostmattermost>= 6.2 < 6.2.36.2.3
mattermostmattermost>= 6.3 < 6.3.36.3.3
mattermostmattermost_server< 5.37.85.37.8
mattermostmattermost_server>= 6.0.0 < 6.1.36.1.3
mattermostmattermost_server>= 6.2.0 < 6.2.36.2.3
mattermostmattermost_server>= 6.3.0 < 6.3.36.3.3

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
cisa8.8HIGH