Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Todo plugin gets crashed and disabled by member
Vulnerability Description
Mattermost fails to handle a null request body in the /add endpoint, allowing a simple member to send a request with null request body to that endpoint and make it crash. After a few repetitions, the plugin is disabled.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Vulnerability Type
未加控制的资源消耗(资源穷尽)
Vulnerability Title
Mattermost 资源管理错误漏洞
Vulnerability Description
Mattermost是美国Mattermost公司的一个开源协作平台。 Mattermost 存在资源管理错误漏洞,该漏洞源于无法处理 add 端点中的空请求正文,从而允许攻击者向该端点发送带有空请求正文的请求并使其崩溃。
CVSS Information
N/A
Vulnerability Type
N/A