CVE-2023-49809
12.12.2023, 09:15
Mattermost fails to handle a null request body in the /add endpoint, allowing a simple member to send a request with null request body to that endpoint and make it crash. After a few repetitions, the plugin is disabled.Enginsight
Vendor | Product | Version |
---|---|---|
mattermost | mattermost_server | 𝑥 ≤ 8.1.5 |
mattermost | mattermost_server | 9.0.0 ≤ 𝑥 ≤ 9.1.0 |
𝑥
= Vulnerable software versions