Mattermost versions 8.1.x before 8.1.12, 9.6.x before 9.6.1, 9.5.x before 9.5.3, 9.4.x before 9.4.5 fail to limit the number of active sessions, which allows an authenticated attacker to crash the server via repeated requests to the getSessions API after flooding the sessions table.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: Mattermost

Published: 2024-04-26T08:25:47.088Z

Updated: 2024-06-04T17:54:30.447Z

Reserved: 2024-04-25T14:18:54.310Z


Link: CVE-2024-4183

JSON object: View

cve-icon NVD Information

Status : Awaiting Analysis

Published: 2024-04-26T09:15:12.717

Modified: 2024-04-26T12:58:17.720


Link: CVE-2024-4183

JSON object: View

cve-icon Redhat Information

No data.

CWE