CVE-2024-28053

Source
https://cve.org/CVERecord?id=CVE-2024-28053
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-28053.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-28053
Aliases
Downstream
Related
Published
2024-03-15T09:08:04.993Z
Modified
2026-08-12T03:51:28.389825449Z
Severity
  • 3.1 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
Summary
Resource Exhaustion via the Invitation Feature
Details

Resource Exhaustion in Mattermost Server versions 8.1.x before 8.1.10 fails to limit the size of the payload that can be read and parsed allowing an attacker to send a very large email payload and crash the server.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/28xxx/CVE-2024-28053.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "8.1.0"
                },
                {
                    "last_affected": "8.1.9"
                }
            ],
            "source": "AFFECTED_FIELD"
        },
        {
            "extracted_events": [
                {
                    "introduced": "8.1.x"
                },
                {
                    "fixed": "8.1.10"
                }
            ],
            "source": "DESCRIPTION"
        }
    ],
    "cwe_ids": [
        "CWE-400"
    ],
    "cna_assigner": "Mattermost"
}
References

Affected packages

Git / github.com/mattermost/mattermost

Affected ranges

Type
GIT
Repo
https://github.com/mattermost/mattermost
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "8.1.0"
        },
        {
            "fixed": "8.1.10"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

@mattermost/client@8.*
@mattermost/client@8.1.1
@mattermost/types@8.*
@mattermost/types@8.1.1
v8.*
v8.1.0
v8.1.0-rc2
v8.1.1
v8.1.1-rc1
v8.1.1-rc2
v8.1.2
v8.1.2-rc1
v8.1.2-rc2
v8.1.3
v8.1.3-rc1
v8.1.3-rc2
v8.1.4
v8.1.4-rc1
v8.1.4-rc2
v8.1.5
v8.1.5-rc1
v8.1.5-rc2
v8.1.6
v8.1.6-rc1
v8.1.7
v8.1.7-rc1
v8.1.7-rc2
v8.1.7-rc3
v8.1.8
v8.1.8-rc1
v8.1.8-rc2
v8.1.9
v8.1.9-rc1
v8.1.9-rc2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-28053.json"