Home
LOW: 3.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:LDefault status
unaffected
Any version
affected
5.5.1
unaffected
Description
Mattermost fails to properly validate a RegExp built off the server URL path, allowing an attacker in control of an enrolled server to mount a Denial Of Service.
Problem types
CWE-400 Uncontrolled Resource Consumption
Product status
Any version
5.5.1
Credits
DoyenSec
References
mattermost.com/security-updates
mattermost.com/security-updates