Upstream information
Description
Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to validate the uniqueness and quantity of task actions within the UpdateRunTaskActions GraphQL operation, which allows an attacker to create task items containing an excessive number of actions triggered by specific posts, overloading the server and leading to a denial-of-service (DoS) condition.SUSE information
Overall state of this security issue: Resolved
This issue is currently rated as having moderate severity.
| CVSS detail | CNA (Mattermost) | 
|---|---|
| Base Score | 6.5 | 
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H | 
| Attack Vector | Network | 
| Attack Complexity | Low | 
| Privileges Required | Low | 
| User Interaction | None | 
| Scope | Unchanged | 
| Confidentiality Impact | None | 
| Integrity Impact | None | 
| Availability Impact | High | 
| CVSSv3 Version | 3.1 | 
SUSE Security Advisories:
- openSUSE-SU-2025:15033-1, published Sun Apr 27 18:49:36 2025
List of released packages
| Product(s) | Fixed package version(s) | References | 
|---|---|---|
| Container suse/sl-micro/6.1/baremetal-os-container:latest Container suse/sl-micro/6.1/base-os-container:latest Container suse/sl-micro/6.1/kvm-os-container:latest Container suse/sl-micro/6.1/rt-os-container:latest | 
 | |
| openSUSE Tumbleweed | 
 | Patchnames: openSUSE-Tumbleweed-2025-15033 | 
SUSE Timeline for this CVE
CVE page created: Thu Apr 24 10:00:06 2025CVE page last modified: Fri Oct 24 12:34:59 2025
