Bug 2277346 (CVE-2024-4183) - CVE-2024-4183 mattermost: fail to limit the number of active sessions
Summary: CVE-2024-4183 mattermost: fail to limit the number of active sessions
Keywords:
Status: NEW
Alias: CVE-2024-4183
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2277347 2277348
Blocks: 2277330
TreeView+ depends on / blocked
 
Reported: 2024-04-26 12:04 UTC by Rohit Keshri
Modified: 2024-05-30 22:23 UTC (History)
11 users (show)

Fixed In Version:
Doc Type: ---
Doc Text:
A flaw was found in Mattermost, where it fails to limit the number of active sessions. This flaw allows an authenticated attacker to crash the server via repeated requests to the getSessions API after flooding the sessions table.
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Rohit Keshri 2024-04-26 12:04:36 UTC
Mattermost versions 8.1.x before 8.1.12, 9.6.x before 9.6.1, 9.5.x before 9.5.3, 9.4.x before 9.4.5 fail to limit the number of active sessions, which allows an authenticated attacker to crash the server via repeated requests to the getSessions API after flooding the sessions table.

https://mattermost.com/security-updates

Comment 1 Rohit Keshri 2024-04-26 12:07:36 UTC
Created purple-mattermost tracking bugs for this issue:

Affects: epel-all [bug 2277347]
Affects: fedora-all [bug 2277348]


Note You need to log in before you can comment on or make changes to this bug.