Mattermost
cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*
- >= 10.11, <= 10.11.8
A denial-of-service vulnerability has been identified in Mattermost versions 10.11.x prior to 10.11.9. The issue arises from the application's failure to properly validate input size before processing hashtags. This oversight enables an authenticated attacker to exhaust CPU resources by sending a single HTTP request that includes a post with thousands of space-separated tokens.
Exploitation of this vulnerability leads to excessive CPU resource consumption, causing a denial-of-service condition on the affected server.
Users can upgrade to Mattermost version 11.3.010.11.10 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.