First published: Wed Nov 23 2022(Updated: )
A denial-of-service vulnerability in Mattermost allows an authenticated user to crash the server via multiple large autoresponder messages.
Credit: responsibledisclosure@mattermost.com responsibledisclosure@mattermost.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mattermost Mattermost | <7.4 | |
<7.4 |
Update Mattermost to version v7.1.4, 7.2.1, 7.3.1, 7.4.0 or higher.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-4044 is a denial-of-service vulnerability in Mattermost that allows an authenticated user to crash the server via multiple large autoresponder messages.
CVE-2022-4044 has a severity of medium, with a CVSS score of 6.5.
An authenticated user can exploit CVE-2022-4044 by sending multiple large autoresponder messages, causing the server to crash.
Yes, there is a fix for CVE-2022-4044. It is recommended to update Mattermost to version 7.4 or above to mitigate the vulnerability.
You can find more information about CVE-2022-4044 on the Mattermost security updates page and the HackerOne report linked in the references.