Mattermost Plugins
cpe:2.3:a:mattermost:mattermost_plugins:*:*:*:*:*:*:*
- <= 2.3.1
A denial-of-service vulnerability has been identified in Mattermost Plugins versions through 2.3.1. The issue arises because the {{/lifecycle}} webhook endpoint does not properly limit the size of incoming JSON payloads. This oversight allows an authenticated attacker to send excessively large payloads, causing memory exhaustion on the server.
Exploitation of this vulnerability leads to memory exhaustion, causing a denial-of-service condition on the server.
Users can upgrade to Mattermost Plugins version 2.3.2 or later, where this vulnerability has been addressed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.