Lucene search

K
prionPRIOn knowledge basePRION:CVE-2024-1953
HistoryFeb 29, 2024 - 11:15 a.m.

Cross site request forgery (csrf)

2024-02-2911:15:00
PRIOn knowledge base
www.prio-n.com
4
mattermost
csrf
api limitation
memory crash
http request

7.1 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.2%

Mattermost versions 8.1.x before 8.1.9, 9.2.x before 9.2.5, 9.3.0, and 9.4.x before 9.4.2 fail to limit the number of role names requested from the API, allowing an authenticated attacker to cause the server to run out of memory and crash by issuing an unusually large HTTP request.

7.1 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.2%

Related for PRION:CVE-2024-1953