CVE-2024-43105: Excessive Resource Consumption via `/export`
Published Aug 23, 2024
·Updated
Mattermost Plugin Channel Export versions <=1.0.0 fail to restrict concurrent runs of the /export command which allows a user to consume excessive resource by running the /export command multiple times at once.
Affected Software
2 affected componentsFixes available
go/github.com/mattermost/mattermost-plugin-channel-export<1.0.1
1.0.1
Mattermost Channel Export Mattermost<=1.0.0
Remediation
Information
Update Mattermost Plugin Channel Export to versions 1.0.1 or higher.
Event History
Aug 23, 2024
CVE Published
via MITRE·07:25 AM
Data Sourced
via MITRE·07:25 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
Affected Software
Advisory Published
via GitHub·09:30 AM
Frequently Asked Questions
1
What are the implications of CVE-2024-43105?
CVE-2024-43105 allows users to launch multiple concurrent executions of the /export command, resulting in potential resource exhaustion.
2
What versions of Mattermost Plugin Channel Export are affected by CVE-2024-43105?
CVE-2024-43105 affects Mattermost Plugin Channel Export versions up to and including 1.0.0.
3
How can I mitigate the risk of CVE-2024-43105?
To mitigate CVE-2024-43105, upgrade to Mattermost Plugin Channel Export version 1.0.1 or later.
4
Is there a patch available for CVE-2024-43105?
Yes, a patch is available in Mattermost Plugin Channel Export version 1.0.1.
5
What steps should I take to secure my system against CVE-2024-43105?
To secure your system against CVE-2024-43105, ensure you update to the latest version of the affected software.