Back

MEDIUM

DoS via Channel Notification Properties

Published Sep 29, 2023

Description

Mattermost fails to enforce character limits in all possible notification props allowing an attacker to send a really long value for a notification_prop resulting in the server consuming an abnormal quantity of computing resources and possibly becoming temporarily unavailable for its users.

Affected products

Remediation

Vendor solution

Update Mattermost Server to versions 7.8.10, 8.0.2, 8.1.1 or higher.

References (4)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner Mattermost
Published Sep 29, 2023
Updated Sep 20, 2024
Reserved Sep 26, 2023

CISA Vulnrichment

Updated Sep 20, 2024

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner Mattermost
Published Sep 29, 2023
Updated Sep 20, 2024