Mattermost
cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*
- >= 11.5.0, <= 11.5.1
- >= 10.11.0, <= 10.11.13
- >= 11.4.0, <= 11.4.3
A denial-of-service vulnerability has been identified in Mattermost versions 11.5.x through 11.5.1, 10.11.x through 10.11.13, and 11.4.x through 11.4.3. The issue arises because these versions do not properly limit the size of the request body for the start meeting API endpoint. This oversight allows authenticated attackers to cause resource exhaustion by sending oversized HTTP POST requests to the meetings API, leading to a denial of service.
Exploitation of this vulnerability can cause resource exhaustion, leading to a denial-of-service condition on the affected Mattermost server.
Users can upgrade to Mattermost versions 11.7.0, 11.6.1, or 11.4.5 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.