GHSA-wj37-mpq9-xrcm

Source
https://github.com/advisories/GHSA-wj37-mpq9-xrcm
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/04/GHSA-wj37-mpq9-xrcm/GHSA-wj37-mpq9-xrcm.json
Aliases
  • CVE-2024-4183
Published
2024-04-26T09:30:34Z
Modified
2024-04-26T19:26:47.145441Z
Summary
Mattermost fails to limit the number of active sessions
Details

Mattermost versions 8.1.x before 8.1.12, 9.6.x before 9.6.1, 9.5.x before 9.5.3, 9.4.x before 9.4.5 fail to limit the number of active sessions, which allows an authenticated attacker to crash the server via repeated requests to the getSessions API after flooding the sessions table.

References

Affected packages

Go / github.com/mattermost/mattermost-server

Affected ranges

Type
SEMVER
Events
Introduced
9.6.0-rc1
Fixed
9.6.1

Database specific

{
    "last_known_affected_version_range": "<= 9.6.0"
}

Go / github.com/mattermost/mattermost-server

Affected ranges

Type
SEMVER
Events
Introduced
9.5.0
Fixed
9.5.3

Database specific

{
    "last_known_affected_version_range": "<= 9.5.2"
}

Go / github.com/mattermost/mattermost-server

Affected ranges

Type
SEMVER
Events
Introduced
9.4.0
Fixed
9.4.5

Database specific

{
    "last_known_affected_version_range": "<= 9.4.4"
}

Go / github.com/mattermost/mattermost-server

Affected ranges

Type
SEMVER
Events
Introduced
8.1.0
Fixed
8.1.12

Database specific

{
    "last_known_affected_version_range": "<= 8.1.11"
}