Mattermost versions 8.1.x before 8.1.12, 9.6.x before 9.6.1, 9.5.x before 9.5.3, 9.4.x before 9.4.5 fail to limit the number of active sessions, which allows an authenticated attacker to crash the server via repeated requests to the getSessions API after flooding the sessions table.
References
Link | Resource |
---|---|
https://mattermost.com/security-updates |
Configurations
No configuration.
History
No history.
Information
Published : 2024-04-26 09:15
Updated : 2024-04-26 12:58
NVD link : CVE-2024-4183
Mitre link : CVE-2024-4183
CVE.ORG link : CVE-2024-4183
JSON object : View
Products Affected
No product.
CWE
CWE-400
Uncontrolled Resource Consumption