Mattermost
cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*
- <= 11.4
- <= 11.0.4
- <= 11.1.3
- <= 11.3.2
- <= 10.11.11
A denial-of-service vulnerability has been identified in Mattermost Plugins versions 10.11.11.0 and 11.0.4, as well as in the 11.1.3 and 11.3.2 releases. These versions fail to properly validate the size of incoming requests to the webhook endpoint. This oversight allows an authenticated attacker to disrupt service by sending oversized requests.
Exploitation of this vulnerability can cause a service disruption by overwhelming the server with large requests, potentially leading to degraded performance or unavailability of the Mattermost instance.
Users can upgrade to Mattermost Plugins version 11.5.011.4.211.3.3 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.