Mattermost
cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*
- >= 11.6, <= 11.6.0
- >= 11.5, <= 11.5.3
- >= 11.4, <= 11.4.4
- >= 10.11, <= 10.11.14
A denial-of-service vulnerability has been identified in Mattermost versions 11.6.0, 11.5.3, 11.4.4, and 10.11.14. The issue arises because these versions do not properly filter nil elements from outgoing webhook attachment payloads before processing. This flaw allows an authenticated user to craft a webhook callback response with a null attachment entry, leading to the termination of the server process.
Exploitation of this vulnerability causes the Mattermost server process to terminate, leading to a denial-of-service condition.
Users can upgrade to Mattermost versions 11.8.0 or 11.7.18 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.