Mattermost fails to enforce character limits in all possible notification props allowing an attacker to send a really long value for a notification_prop resulting in the server consuming an abnormal quantity of computing resources and possibly becoming temporarily unavailable for its users.
Solution:
The product does not properly control the allocation and maintenance of a limited resource.
Link | Tags |
---|---|
https://mattermost.com/security-updates | vendor advisory |