Mattermost
cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*
- >= 11.6, <= 11.6.0
- >= 11.5, <= 11.5.3
- >= 11.4, <= 11.4.4
- >= 10.11, <= 10.11.14
A denial-of-service vulnerability has been identified in Mattermost versions 11.6.0, 11.5.3, 11.4.4, and 10.11.14. The issue arises from the failure to properly validate user input in API request handlers, allowing an authenticated attacker to crash the plugin process. This can be achieved by sending a crafted HTTP request to the PR details endpoint.
Exploitation of this vulnerability leads to a crash of the plugin process, causing a denial-of-service condition.
Users can upgrade to Mattermost versions 11.8.0 or 11.7.18 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.