Mattermost
cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*
- >= 10.4.0, <= 10.4.2
- >= 10.5.0, <= 10.5.0
- >= 9.11.0, <= 9.11.10
A denial-of-service vulnerability has been identified in the Mattermost Playbooks plugin, specifically within versions 10.4.x prior to 10.4.2, 10.5.x prior to 10.5.0, and 9.11.x prior to 9.11.10. The issue arises because these versions do not properly validate the properties used by the RetrospectivePost custom post type. This lack of validation allows an attacker to create a post with maliciously crafted properties, leading to a denial-of-service condition that affects the web application for all users.
Exploitation of this vulnerability causes a denial-of-service condition on the web application, impacting all users.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.