CVE-2024-1953
published 2024-02-29CVE-2024-1953: Mattermost versions 8.1.x before 8.1.9, 9.2.x before 9.2.5, 9.3.0, and 9.4.x before 9.4.2 fail to limit the number of role names requested from the API…
PriorityP421medium4.3CVSS 3.1
AVNACLPRLUINSUCNINAL
EPSS
0.51%
40.4th percentile
Mattermost versions 8.1.x before 8.1.9, 9.2.x before 9.2.5, 9.3.0, and 9.4.x before 9.4.2 fail to limit the number of role names requested from the API, allowing an authenticated attacker to cause the server to run out of memory and crash by issuing an unusually large HTTP request.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | mattermost_mattermost-server | >= 9.2.0+incompatible < 9.2.5+incompatible | 9.2.5+incompatible |
| github.com | mattermost_mattermost-server | >= 9.3.0+incompatible < 9.3.1+incompatible | 9.3.1+incompatible |
| github.com | mattermost_mattermost-server | >= 9.4.0+incompatible < 9.4.2+incompatible | 9.4.2+incompatible |
| github.com | mattermost_mattermost_server_v8 | >= 0 < 8.1.9 | 8.1.9 |
| github.com | mattermost_mattermost_server_v8 | >= 9.2.0 < 9.2.5 | 9.2.5 |
| github.com | mattermost_mattermost_server_v8 | >= 9.3.0 < 9.3.1 | 9.3.1 |
| github.com | mattermost_mattermost_server_v8 | >= 9.4.0 < 9.4.2 | 9.4.2 |
| mattermost | mattermost | — | — |
| mattermost | mattermost | 8.1.0 – 8.1.8 | — |
| mattermost | mattermost | 9.2.0 – 9.2.4 | — |
| mattermost | mattermost | 9.4.0 – 9.4.1 | — |
| mattermost | mattermost_server | — | — |
| mattermost | mattermost_server | >= 8.1.0 < 8.1.9 | 8.1.9 |
| mattermost | mattermost_server | >= 9.2.0 < 9.2.5 | 9.2.5 |
| mattermost | mattermost_server | >= 9.4.0 < 9.4.2 | 9.4.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Mattermost fails to limit the number of role names in github.com/mattermost/mattermost-server
osv·2024-06-28
CVE-2024-1953 Mattermost fails to limit the number of role names in github.com/mattermost/mattermost-server
Mattermost fails to limit the number of role names in github.com/mattermost/mattermost-server
Mattermost fails to limit the number of role names in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.9.
OSV
Mattermost fails to limit the number of role names
osv·2024-02-29
CVE-2024-1953 [MEDIUM] Mattermost fails to limit the number of role names
Mattermost fails to limit the number of role names
Mattermost versions 8.1.x before 8.1.9, 9.2.x before 9.2.5, 9.3.0, and 9.4.x before 9.4.2 fail to limit the number of role names requested from the API, allowing an authenticated attacker to cause the server to run out of memory and crash by issuing an unusually large HTTP request.
GHSA
Mattermost fails to limit the number of role names
ghsa·2024-02-29
CVE-2024-1953 [MEDIUM] CWE-400 Mattermost fails to limit the number of role names
Mattermost fails to limit the number of role names
Mattermost versions 8.1.x before 8.1.9, 9.2.x before 9.2.5, 9.3.0, and 9.4.x before 9.4.2 fail to limit the number of role names requested from the API, allowing an authenticated attacker to cause the server to run out of memory and crash by issuing an unusually large HTTP request.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-02-29
Published