Mattermost fails to properly sanitize the request to /api/v4/redirect_location allowing an attacker, sending a specially crafted request to /api/v4/redirect_location, to fill up the memory due to caching large items.
Solution:
The product does not properly control the allocation and maintenance of a limited resource.
Link | Tags |
---|---|
https://mattermost.com/security-updates | vendor advisory |