PT-2026-97058 · Mattermost · Mattermost
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Mattermost versions 11.7.0 through 11.7.10
Mattermost versions 11.8.0 through 11.8.5
Mattermost versions 11.9.0 through 11.9.1
Mattermost versions 11.10.0 through 11.10.1
Description
An authenticated user can cause a denial of service by exhausting server memory. This occurs because the software fails to enforce a request body size limit during Cross-Site Request Forgery (CSRF) validation—a security mechanism used to prevent unauthorized commands from being transmitted from a user that the web application trusts—when processing requests sent to a plugin endpoint.
Recommendations
Update Mattermost versions 11.7.0 through 11.7.10 to a version newer than 11.7.10.
Update Mattermost versions 11.8.0 through 11.8.5 to a version newer than 11.8.5.
Update Mattermost versions 11.9.0 through 11.9.1 to a version newer than 11.9.1.
Update Mattermost versions 11.10.0 through 11.10.1 to a version newer than 11.10.1.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mattermost