CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 4.3. It may lead to a denial-of-service condition.
CVE
CVE-2024-28949
Severity
MEDIUM
CVSS
4.3
EPSS
0.56%
Original NVD Description
Mattermost Server versions 9.5.x before 9.5.2, 9.4.x before 9.4.4, 9.3.x before 9.3.3, 8.1.x before 8.1.11 don't limit the number of user preferences which allows an attacker to send a large number of user preferences potentially causing denial of service.
Related CVEs
Other vulnerabilities affecting the same vendor(s)