Security Advisory

CVE-2024-28949

4.3
MEDIUM

Vulnerability Description

Mattermost Server versions 9.5.x before 9.5.2, 9.4.x before 9.4.4, 9.3.x before 9.3.3, 8.1.x before 8.1.11 don't limit the number of user preferences which allows an attacker to send a large number of user preferences potentially causing denial of service.
Published Date April 5, 2024
Official Source NIST NVD Advisory