CVE-2024-4183: Medium severity Mattermost Mattermost Server vulnerability
Mattermost versions 8.1.x before 8.1.12, 9.6.x before 9.6.1, 9.5.x before 9.5.3, 9.4.x before 9.4.5 fail to limit the number of active sessions, which allows an authenticated attacker to crash the server via repeated requests to the getSessions API after flooding the sessions table.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
go/github.com/mattermost/mattermost-serverto a version that resolves this vulnerability.Fixed in 8.1.12 - Upgrade
Upgrade
go/github.com/mattermost/mattermost-serverto a version that resolves this vulnerability.Fixed in 9.4.5 - Upgrade
Upgrade
go/github.com/mattermost/mattermost-serverto a version that resolves this vulnerability.Fixed in 9.5.3 - Upgrade
Upgrade
go/github.com/mattermost/mattermost-serverto a version that resolves this vulnerability.Fixed in 9.6.1 - Upgrade
Upgrade
Mattermost Serverto a version that resolves this vulnerability.Fixed in 9.7.0 - Upgrade
Upgrade
Mattermost Serverto a version that resolves this vulnerability.Fixed in 9.6.1 - Upgrade
Upgrade
Mattermost Serverto a version that resolves this vulnerability.Fixed in 9.5.3 - Upgrade
Upgrade
Mattermost Serverto a version that resolves this vulnerability.Fixed in 9.4.5 - Upgrade
Upgrade
Mattermost Serverto a version that resolves this vulnerability.Fixed in 8.1.12
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4183?
CVE-2024-4183 is considered a high severity vulnerability due to its potential to crash the Mattermost server.
How do I fix CVE-2024-4183?
To mitigate CVE-2024-4183, upgrade Mattermost to version 8.1.12, 9.4.5, 9.5.3, or 9.6.1 or later.
What is the impact of CVE-2024-4183?
CVE-2024-4183 allows an authenticated attacker to crash the Mattermost server by flooding the sessions table.
Which versions of Mattermost are affected by CVE-2024-4183?
Mattermost versions 8.1.x before 8.1.12, 9.6.x before 9.6.1, 9.5.x before 9.5.3, and 9.4.x before 9.4.5 are affected by CVE-2024-4183.
Is an authenticated user necessary to exploit CVE-2024-4183?
Yes, CVE-2024-4183 requires an authenticated user to exploit the vulnerability through repeated requests.