NA

CVE-2024-4183

Published: 26/04/2024 Updated: 26/04/2024

Vulnerability Summary

Mattermost versions 8.1.x prior to 8.1.12, 9.6.x prior to 9.6.1, 9.5.x prior to 9.5.3, 9.4.x prior to 9.4.5 fail to limit the number of active sessions, which allows an authenticated malicious user to crash the server via repeated requests to the getSessions API after flooding the sessions table.