CVE-2024-4183
published 2024-04-26CVE-2024-4183: Mattermost versions 8.1.x before 8.1.12, 9.6.x before 9.6.1, 9.5.x before 9.5.3, 9.4.x before 9.4.5 fail to limit the number of active sessions, which allows…
PriorityP336medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
0.61%
45.6th percentile
Mattermost versions 8.1.x before 8.1.12, 9.6.x before 9.6.1, 9.5.x before 9.5.3, 9.4.x before 9.4.5 fail to limit the number of active sessions, which allows an authenticated attacker to crash the server via repeated requests to the getSessions API after flooding the sessions table.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | mattermost_mattermost-server | >= 8.1.0 < 8.1.12 | 8.1.12 |
| github.com | mattermost_mattermost-server | >= 8.1.0+incompatible < 8.1.12+incompatible | 8.1.12+incompatible |
| github.com | mattermost_mattermost-server | >= 9.4.0 < 9.4.5 | 9.4.5 |
| github.com | mattermost_mattermost-server | >= 9.4.0+incompatible < 9.4.5+incompatible | 9.4.5+incompatible |
| github.com | mattermost_mattermost-server | >= 9.5.0 < 9.5.3 | 9.5.3 |
| github.com | mattermost_mattermost-server | >= 9.5.0+incompatible < 9.5.3+incompatible | 9.5.3+incompatible |
| github.com | mattermost_mattermost-server | >= 9.6.0-rc1 < 9.6.1 | 9.6.1 |
| github.com | mattermost_mattermost-server | >= 9.6.0-rc1+incompatible < 9.6.1+incompatible | 9.6.1+incompatible |
| mattermost | mattermost | 8.1.0 – 8.1.11 | — |
| mattermost | mattermost | 9.4.0 – 9.4.4 | — |
| mattermost | mattermost | 9.5.0 – 9.5.2 | — |
| mattermost | mattermost | 9.6.0 – 8.1.10 | — |
| mattermost | mattermost_server | >= 8.1.0 < 8.1.12 | 8.1.12 |
| mattermost | mattermost_server | >= 9.4.0 < 9.4.5 | 9.4.5 |
| mattermost | mattermost_server | >= 9.5.0 < 9.5.3 | 9.5.3 |
| mattermost | mattermost_server | >= 9.6.0 < 9.6.1 | 9.6.1 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Mattermost fails to limit the number of active sessions in github.com/mattermost/mattermost-server
osv·2024-06-05
CVE-2024-4183 Mattermost fails to limit the number of active sessions in github.com/mattermost/mattermost-server
Mattermost fails to limit the number of active sessions in github.com/mattermost/mattermost-server
Mattermost fails to limit the number of active sessions in github.com/mattermost/mattermost-server
OSV
Mattermost fails to limit the number of active sessions
osv·2024-04-26
CVE-2024-4183 [MEDIUM] Mattermost fails to limit the number of active sessions
Mattermost fails to limit the number of active sessions
Mattermost versions 8.1.x before 8.1.12, 9.6.x before 9.6.1, 9.5.x before 9.5.3, 9.4.x before 9.4.5 fail to limit the number of active sessions, which allows an authenticated attacker to crash the server via repeated requests to the getSessions API after flooding the sessions table.
GHSA
Mattermost fails to limit the number of active sessions
ghsa·2024-04-26
CVE-2024-4183 [MEDIUM] CWE-400 Mattermost fails to limit the number of active sessions
Mattermost fails to limit the number of active sessions
Mattermost versions 8.1.x before 8.1.12, 9.6.x before 9.6.1, 9.5.x before 9.5.3, 9.4.x before 9.4.5 fail to limit the number of active sessions, which allows an authenticated attacker to crash the server via repeated requests to the getSessions API after flooding the sessions table.
Red Hat
mattermost: fail to limit the number of active sessions
vendor_redhat·2024-04-26·CVSS 4.3
CVE-2024-4183 [MEDIUM] CWE-400 mattermost: fail to limit the number of active sessions
mattermost: fail to limit the number of active sessions
Mattermost versions 8.1.x before 8.1.12, 9.6.x before 9.6.1, 9.5.x before 9.5.3, 9.4.x before 9.4.5 fail to limit the number of active sessions, which allows an authenticated attacker to crash the server via repeated requests to the getSessions API after flooding the sessions table.
A flaw was found in Mattermost, where it fails to limit the number of active sessions. This flaw allows an authenticated attacker to crash the server via repeated requests to the getSessions API after flooding the sessions table.
Package: rhacm2/acm-grafana-rhel8 (Red Hat Advanced Cluster Management for Kubernetes 2) - Fix deferred
Package: advanced-cluster-security/rhacs-docs-rhel8 (Red Hat Advanced Cluster Security 3) - Fix deferred
Package: advance
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-04-26
Published