Lucene search

K
osvGoogleOSV:GO-2024-2541
HistoryJun 28, 2024 - 3:28 p.m.

Mattermost vulnerable to denial of service via large number of emoji reactions in github.com/mattermost/mattermost-server

2024-06-2815:28:53
Google
osv.dev
3
mattermost
dos
vulnerability
emoji
reactions

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

AI Score

4.3

Confidence

High

Mattermost vulnerable to denial of service via large number of emoji reactions in github.com/mattermost/mattermost-server.

NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.

(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)

The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.8.

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

AI Score

4.3

Confidence

High