CVE-2024-39810
Server crash via Elasticsearch certificate file
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Mattermost versions 9.5.x <= 9.5.7 and 9.10.x <= 9.10.0 fail to time limit and size limit the CA path file in the ElasticSearch configuration which allows a System Role with access to the Elasticsearch system console to add any file as a CA path field, such as /dev/zero and, after testing the connection, cause the application to crash.
Las versiones 9.5.x <= 9.5.7 y 9.10.x <= 9.10.0 de Mattermost no limitan el tiempo ni el tamaño del archivo de ruta de CA en la configuración de ElasticSearch, lo que permite que una función del sistema con acceso a la consola del sistema Elasticsearch agregue cualquier archivo. como un campo de ruta de CA, como /dev/zero y, después de probar la conexión, provocar que la aplicación falle.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2024-08-20 CVE Reserved
- 2024-08-22 CVE Published
- 2024-08-22 CVE Updated
- 2024-08-24 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-400: Uncontrolled Resource Consumption
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mattermost Search vendor "Mattermost" | Mattermost Search vendor "Mattermost" for product "Mattermost" | >= 9.5.0 <= 9.5.7 Search vendor "Mattermost" for product "Mattermost" and version " >= 9.5.0 <= 9.5.7" | en |
Affected
| ||||||
Mattermost Search vendor "Mattermost" | Mattermost Search vendor "Mattermost" for product "Mattermost" | 9.10.0 Search vendor "Mattermost" for product "Mattermost" and version "9.10.0" | en |
Affected
|