MEDIUM6.5
GHSA-v42f-hq78-8c5m
Denial of service in Mattermost
Quick fix
GHSA-v42f-hq78-8c5m — github.com/mattermost/mattermost-server: upgrade to the fixed version with the command below.
go get github.com/mattermost/mattermost-server@v7.1.4Details
A denial-of-service vulnerability in the Mattermost allows an authenticated user to crash the server via multiple requests to one of the API endpoints which could fetch a large amount of data.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/mattermost/mattermost-server
Introduced in:
0Fixed in: 7.1.4Fix
go get github.com/mattermost/mattermost-server@v7.1.4Go/github.com/mattermost/mattermost-server
Introduced in:
7.2.0Fixed in: 7.2.1Fix
go get github.com/mattermost/mattermost-server@v7.2.1Go/github.com/mattermost/mattermost-server
Introduced in:
7.3.0Fixed in: 7.3.1Fix
go get github.com/mattermost/mattermost-server@v7.3.1