cbcvebase.
CVE-2024-28053
published 2024-03-15

CVE-2024-28053: Resource Exhaustion in Mattermost Server versions 8.1.x before 8.1.10 fails to limit the size of the payload that can be read and parsed allowing an attacker…

PriorityP433medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
0.51%
40.0th percentile
Resource Exhaustion in Mattermost Server versions 8.1.x before 8.1.10 fails to limit the size of the payload that can be read and parsed allowing an attacker to send a very large email payload and crash the server.

Affected

6 ranges
VendorProductVersion rangeFixed in
github.commattermost_mattermost-server>= 0 < 0.0.0-20240209181221-674f549daf0e0.0.0-20240209181221-674f549daf0e
github.commattermost_mattermost-server_v5>= 0 < 0.0.0-20240209181221-674f549daf0e0.0.0-20240209181221-674f549daf0e
github.commattermost_mattermost-server_v6>= 0 < 0.0.0-20240209181221-674f549daf0e0.0.0-20240209181221-674f549daf0e
github.commattermost_mattermost_server_v8>= 0 < 0.0.0-20240209181221-674f549daf0e0.0.0-20240209181221-674f549daf0e
mattermostmattermost8.1.0 – 8.1.9
mattermostmattermost_server>= 8.1.0 < 8.1.108.1.10
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.