First published: Wed Nov 23 2022(Updated: )
A denial-of-service vulnerability in the Mattermost allows an authenticated user to crash the server via multiple requests to one of the API endpoints which could fetch a large amount of data.
Credit: responsibledisclosure@mattermost.com responsibledisclosure@mattermost.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mattermost Mattermost | ||
Update Mattermost to version v7.4.0 or higher.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-4045 is a denial-of-service vulnerability in Mattermost that allows an authenticated user to crash the server.
An authenticated user can exploit CVE-2022-4045 by sending multiple requests to one of the API endpoints, fetching a large amount of data which can crash the server.
CVE-2022-4045 has a severity rating of medium (6.5).
The Mattermost software is affected by CVE-2022-4045.
To fix CVE-2022-4045, update Mattermost to the latest version and apply the security patches provided by the vendor.