Loading HuntDB...

GHSA-3487-3j7c-7gwj

GitHub Security Advisory

Mattermost Uncontrolled Resource Consumption vulnerability

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

Mattermost fails to limit the log size of server logs allowing an attacker sending specially crafted requests to different endpoints to potentially overflow the log.

Affected Packages

Go github.com/mattermost/mattermost/server/v8
Affected versions: 9.1.0 (fixed in 9.1.1)
Go github.com/mattermost/mattermost/server/v8
Affected versions: 9.0.0 (fixed in 9.0.2)
Go github.com/mattermost/mattermost/server/v8
Affected versions: 0 (fixed in 8.1.4)
Go github.com/mattermost/mattermost-server/v6
Affected versions: 0 (fixed in 7.8.13)

Related CVEs

Key Information

GHSA ID
GHSA-3487-3j7c-7gwj
Published
November 27, 2023 12:30 PM
Last Modified
December 4, 2023 3:20 PM
CVSS Score
5.0 /10
Primary Ecosystem
Go
Primary Package
github.com/mattermost/mattermost/server/v8
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 30, 2025 6:36 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.