cbcvebase.
CVE-2024-1953
published 2024-02-29

CVE-2024-1953: Mattermost versions 8.1.x before 8.1.9, 9.2.x before 9.2.5, 9.3.0, and 9.4.x before 9.4.2 fail to limit the number of role names requested from the API…

medium4.3CVSS 3.1
AVNACLPRLUINSUCNINAL
Mattermost versions 8.1.x before 8.1.9, 9.2.x before 9.2.5, 9.3.0, and 9.4.x before 9.4.2 fail to limit the number of role names requested from the API, allowing an authenticated attacker to cause the server to run out of memory and crash by issuing an unusually large HTTP request.

Affected

15 ranges
VendorProductVersion rangeFixed in
github.commattermost_mattermost-server>= 9.2.0+incompatible < 9.2.5+incompatible9.2.5+incompatible
github.commattermost_mattermost-server>= 9.3.0+incompatible < 9.3.1+incompatible9.3.1+incompatible
github.commattermost_mattermost-server>= 9.4.0+incompatible < 9.4.2+incompatible9.4.2+incompatible
github.commattermost_mattermost_server_v8>= 0 < 8.1.98.1.9
github.commattermost_mattermost_server_v8>= 9.2.0 < 9.2.59.2.5
github.commattermost_mattermost_server_v8>= 9.3.0 < 9.3.19.3.1
github.commattermost_mattermost_server_v8>= 9.4.0 < 9.4.29.4.2
mattermostmattermost
mattermostmattermost8.1.0 – 8.1.8
mattermostmattermost9.2.0 – 9.2.4
mattermostmattermost9.4.0 – 9.4.1
mattermostmattermost_server
mattermostmattermost_server>= 8.1.0 < 8.1.98.1.9
mattermostmattermost_server>= 9.2.0 < 9.2.59.2.5
mattermostmattermost_server>= 9.4.0 < 9.4.29.4.2