CVE-2024-28053: Resource Exhaustion via the Invitation Feature
Published Mar 15, 2024
·Updated
Resource Exhaustion in Mattermost Server versions 8.1.x before 8.1.10 fails to limit the size of the payload that can be read and parsed allowing an attacker to send a very large email payload and crash the server.
Affected Software
5 affected componentsFixes available
go/github.com/mattermost/mattermost-server/v6<0.0.0-20240209181221-674f549daf0e
0.0.0-20240209181221-674f549daf0e
go/github.com/mattermost/mattermost-server/v5<0.0.0-20240209181221-674f549daf0e
0.0.0-20240209181221-674f549daf0e
go/github.com/mattermost/mattermost-server<0.0.0-20240209181221-674f549daf0e
0.0.0-20240209181221-674f549daf0e
go/github.com/mattermost/mattermost/server/v8<0.0.0-20240209181221-674f549daf0e
0.0.0-20240209181221-674f549daf0e
Mattermost Mattermost Server>=8.1.0<8.1.10
Remediation
Information
Update Mattermost Server to versions 9.5.0, 8.1.10 or higher.
Event History
Mar 15, 2024
CVE Published
via MITRE·09:08 AM
Data Sourced
via MITRE·09:08 AM
RemedyDescriptionSeverityWeakness
Advisory Published
via GitHub·09:30 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-28053?
CVE-2024-28053 is classified as a high severity vulnerability due to its potential to crash the Mattermost server.
2
How do I fix CVE-2024-28053?
To fix CVE-2024-28053, update your Mattermost Server to version 8.1.10 or later.
3
What versions of Mattermost Server are affected by CVE-2024-28053?
CVE-2024-28053 affects Mattermost Server versions 8.1.x before 8.1.10.
4
What type of attack does CVE-2024-28053 enable?
CVE-2024-28053 allows an attacker to perform a resource exhaustion attack by sending a very large email payload.
5
Where can I find more information about CVE-2024-28053?
Additional details on CVE-2024-28053 can typically be found in security advisories published by Mattermost.