Mattermost Plugins
cpe:2.3:a:mattermost:mattermost_plugins:*:*:*:*:*:*:*
- <= 2.1.3.0
A denial-of-service vulnerability has been identified in Mattermost Plugins versions through 2.1.3.0. The issue arises because the {{/changes}} webhook endpoint does not properly limit the size of incoming JSON payloads. This oversight enables authenticated attackers to send excessively large payloads, causing memory exhaustion and disrupting service.
Exploitation of this vulnerability leads to memory exhaustion on the server, causing a denial-of-service condition where the application becomes unresponsive or unavailable.
Users can upgrade to Mattermost Plugins version 2.1.3.1 or later, where this vulnerability has been addressed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.