cbcvebase.
CVE-2024-1953
published 2024-02-29

CVE-2024-1953: Mattermost versions 8.1.x before 8.1.9, 9.2.x before 9.2.5, 9.3.0, and 9.4.x before 9.4.2 fail to limit the number of role names requested from the API…

PriorityP421medium4.3CVSS 3.1
AVNACLPRLUINSUCNINAL
EPSS
0.51%
40.4th percentile
Mattermost versions 8.1.x before 8.1.9, 9.2.x before 9.2.5, 9.3.0, and 9.4.x before 9.4.2 fail to limit the number of role names requested from the API, allowing an authenticated attacker to cause the server to run out of memory and crash by issuing an unusually large HTTP request.

Affected

15 ranges
VendorProductVersion rangeFixed in
github.commattermost_mattermost-server>= 9.2.0+incompatible < 9.2.5+incompatible9.2.5+incompatible
github.commattermost_mattermost-server>= 9.3.0+incompatible < 9.3.1+incompatible9.3.1+incompatible
github.commattermost_mattermost-server>= 9.4.0+incompatible < 9.4.2+incompatible9.4.2+incompatible
github.commattermost_mattermost_server_v8>= 0 < 8.1.98.1.9
github.commattermost_mattermost_server_v8>= 9.2.0 < 9.2.59.2.5
github.commattermost_mattermost_server_v8>= 9.3.0 < 9.3.19.3.1
github.commattermost_mattermost_server_v8>= 9.4.0 < 9.4.29.4.2
mattermostmattermost
mattermostmattermost8.1.0 – 8.1.8
mattermostmattermost9.2.0 – 9.2.4
mattermostmattermost9.4.0 – 9.4.1
mattermostmattermost_server
mattermostmattermost_server>= 8.1.0 < 8.1.98.1.9
mattermostmattermost_server>= 9.2.0 < 9.2.59.2.5
mattermostmattermost_server>= 9.4.0 < 9.4.29.4.2
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.