Mattermost fails to deduplicate input IDs allowing a simple user to cause the application to consume excessive resources and possibly crash by sending a specially crafted request to /api/v4/users/ids with multiple identical IDs.
Solution:
The product does not properly control the allocation and maintenance of a limited resource.
Link | Tags |
---|---|
https://mattermost.com/security-updates | vendor advisory |