Mattermost
cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*
- >= 11.6, <= 11.6.0
- >= 11.5, <= 11.5.3
- >= 11.4, <= 11.4.4
- >= 10.11, <= 10.11.14
A denial-of-service vulnerability has been identified in Mattermost versions 11.6.0, 11.5.3, 11.4.4, and 10.11.14. The issue arises because the application fails to archive channels before removing persistent notifications. This flaw allows an authenticated user to crash the server by carefully timing the sending of a persistent notification message to coincide with the server's deletion of existing notifications and the archiving of the channel.
Exploitation of this vulnerability can lead to a server crash, causing a denial-of-service condition where the server becomes unresponsive or unavailable.
Users can upgrade to Mattermost versions 11.8.0 or 11.7.18 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.