Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.0, 10.9.x <= 10.9.3 fail to validate import data which allows a system admin to crash the server via the bulk import feature.
The product dereferences a pointer that it expects to be valid but is NULL.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mattermost_server | Mattermost | 9.11.0 (including) | 9.11.18 (excluding) |
Mattermost_server | Mattermost | 10.5.0 (including) | 10.5.9 (excluding) |
Mattermost_server | Mattermost | 10.8.0 (including) | 10.8.4 (excluding) |
Mattermost_server | Mattermost | 10.9.0 (including) | 10.9.4 (excluding) |
Mattermost_server | Mattermost | 10.10.0 (including) | 10.10.0 (including) |