CVE-2022-0903
10.03.2022, 17:45
A call stack overflow bug in the SAML login feature in Mattermost server in versions up to and including 6.3.2 allows an attacker to crash the server via submitting a maliciously crafted POST body.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| mattermost | mattermost_server | 𝑥 < 5.37.8 |
| mattermost | mattermost_server | 6.0.0 ≤ 𝑥 < 6.1.3 |
| mattermost | mattermost_server | 6.2.0 ≤ 𝑥 < 6.2.3 |
| mattermost | mattermost_server | 6.3.0 ≤ 𝑥 < 6.3.3 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| mattermost | mattermost | 6.3 ≤ 𝑥 < 6.3.3 | CNA |
| mattermost | mattermost | 6.2 ≤ 𝑥 < 6.2.3 | CNA |
| mattermost | mattermost | 6.1 ≤ 𝑥 < 6.1.3 | CNA |
| mattermost | mattermost | 5.37 ≤ 𝑥 < 5.37.8 | CNA |
Common Weakness Enumeration