VDB
Sign up
MEDIUM4.3

GHSA-c37r-v8jx-7cv2

Mattermost Uncontrolled Resource Consumption vulnerability

Quick fix

GHSA-c37r-v8jx-7cv2 — github.com/mattermost/mattermost/server/v8: upgrade to the fixed version with the command below.

go get github.com/mattermost/mattermost/server/v8@v9.1.1

Details

Mattermost fails to properly limit the characters allowed in different fields of a block in Mattermost Boards allowing a attacker to consume excessive resources, possibly leading to Denial of Service, by patching the field of a block using a specially crafted string. 

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/mattermost/mattermost/server/v8
Introduced in: 9.1.0Fixed in: 9.1.1
Fixgo get github.com/mattermost/mattermost/server/v8@v9.1.1
Go/github.com/mattermost/mattermost/server/v8
Introduced in: 9.0.0Fixed in: 9.0.2
Fixgo get github.com/mattermost/mattermost/server/v8@v9.0.2
Go/github.com/mattermost/mattermost/server/v8
Introduced in: 0Fixed in: 8.1.4
Fixgo get github.com/mattermost/mattermost/server/v8@v8.1.4
Go/github.com/mattermost/mattermost-server/v6
Introduced in: 0Fixed in: 7.8.13
Fixgo get github.com/mattermost/mattermost-server/v6@v7.8.13

References