CVE-2024-1953: Medium severity mattermost vulnerability
Mattermost versions 8.1.x before 8.1.9, 9.2.x before 9.2.5, 9.3.0, and 9.4.x before 9.4.2 fail to limit the number of role names requested from the API, allowing an authenticated attacker to cause the server to run out of memory and crash by issuing an unusually large HTTP request.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1953?
CVE-2024-1953 has a high severity as it allows an authenticated attacker to potentially crash the server by overwhelming it with large HTTP requests.
How do I fix CVE-2024-1953?
To fix CVE-2024-1953, update Mattermost to version 8.1.9, 9.2.5, 9.3.1, or 9.4.2 or later.
Which Mattermost versions are affected by CVE-2024-1953?
Mattermost versions earlier than 8.1.9, 9.2.5, 9.3.0, and 9.4.2 are affected by CVE-2024-1953.
What type of attack does CVE-2024-1953 describe?
CVE-2024-1953 describes a denial-of-service attack where the server can run out of memory due to excessively large role name requests.
Is CVE-2024-1953 related to authentication?
Yes, CVE-2024-1953 requires the attacker to be authenticated in order to exploit the vulnerability.