CVE-2024-28949: Mattermost Server
Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.
Mattermost Server versions 9.5.x before 9.5.2, 9.4.x before 9.4.4, 9.3.x before 9.3.3, 8.1.x before 8.1.11 don't limit the number of user preferences which allows an attacker to send a large number of user preferences potentially causing denial of service.
Affected products
- Mattermost Mattermost Server: from 8.1.0, before 8.1.11 (fixed in 8.1.11); from 9.3.0, before 9.3.3 (fixed in 9.3.3); from 9.4.0, before 9.4.4 (fixed in 9.4.4); from 9.5.0, before 9.5.2 (fixed in 9.5.2)
Published 2024-04-05. Last modified 2026-06-17.