CVE-2024-28053
published 2024-03-15CVE-2024-28053: Resource Exhaustion in Mattermost Server versions 8.1.x before 8.1.10 fails to limit the size of the payload that can be read and parsed allowing an attacker…
PriorityP433medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
0.51%
40.0th percentile
Resource Exhaustion in Mattermost Server versions 8.1.x before 8.1.10 fails to limit the size of the payload that can be read and parsed allowing an attacker to send a very large email payload and crash the server.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | mattermost_mattermost-server | >= 0 < 0.0.0-20240209181221-674f549daf0e | 0.0.0-20240209181221-674f549daf0e |
| github.com | mattermost_mattermost-server_v5 | >= 0 < 0.0.0-20240209181221-674f549daf0e | 0.0.0-20240209181221-674f549daf0e |
| github.com | mattermost_mattermost-server_v6 | >= 0 < 0.0.0-20240209181221-674f549daf0e | 0.0.0-20240209181221-674f549daf0e |
| github.com | mattermost_mattermost_server_v8 | >= 0 < 0.0.0-20240209181221-674f549daf0e | 0.0.0-20240209181221-674f549daf0e |
| mattermost | mattermost | 8.1.0 – 8.1.9 | — |
| mattermost | mattermost_server | >= 8.1.0 < 8.1.10 | 8.1.10 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Mattermost Server Resource Exhaustion in github.com/mattermost/mattermost-server
osv·2024-12-18
CVE-2024-28053 Mattermost Server Resource Exhaustion in github.com/mattermost/mattermost-server
Mattermost Server Resource Exhaustion in github.com/mattermost/mattermost-server
Mattermost Server Resource Exhaustion in github.com/mattermost/mattermost-server
OSV
Mattermost Server Resource Exhaustion
osv·2024-03-15
CVE-2024-28053 [LOW] Mattermost Server Resource Exhaustion
Mattermost Server Resource Exhaustion
Resource Exhaustion in Mattermost Server versions 8.1.x before 8.1.10 fails to limit the size of the payload that can be read and parsed allowing an attacker to send a very large email payload and crash the server.
GHSA
Mattermost Server Resource Exhaustion
ghsa·2024-03-15
CVE-2024-28053 [LOW] CWE-400 Mattermost Server Resource Exhaustion
Mattermost Server Resource Exhaustion
Resource Exhaustion in Mattermost Server versions 8.1.x before 8.1.10 fails to limit the size of the payload that can be read and parsed allowing an attacker to send a very large email payload and crash the server.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-03-15
Published