Mattermost fails to deduplicate input IDs allowing a simple user to cause the application to consume excessive resources and possibly crash by sending a specially crafted request to /api/v4/users/ids with multiple identical IDs.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mattermost_server | Mattermost | * | 7.8.11 (excluding) |
Mattermost_server | Mattermost | 8.0.0 (including) | 8.0.3 (excluding) |
Mattermost_server | Mattermost | 8.1.0 (including) | 8.1.2 (excluding) |