CVE-2024-47401
Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1 and 9.5.x <= 9.5.9 fail to prevent detailed error messages from being displayed in Playbooks which allows an attacker to generate a large response and cause an amplified GraphQL response which in turn could cause the application to crash by sending a specially crafted request to Playbooks.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Base score: 7.5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.46%
- Percentile among all scored CVEs: 38
- Score date: 10/6/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
🎯 ATT&CK techniques
How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.
- Exploitation
T1190Exploit Public-Facing Applicationinitial access85 % - Primary impact
T1499.004Application or System Exploitationimpact80 %
AV:N/AC:L/PR:N sin UI permite acceso remoto no autenticado (T1190). La amplificación de respuesta GraphQL causa DoS por consumo de recursos (T1499.004).
Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.
🛡️ ATT&CK mitigations that cover these techniques
Affected technologies (1)
CWEs
- CWE-770
References
Raw JSON (NVD)
Show
{
"id": "CVE-2024-47401",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-47401",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-10-29T12:51:53.557835Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "responsibledisclosure@mattermost.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 2.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "responsibledisclosure@mattermost.com",
"affectedData": [
{
"vendor": "Mattermost",
"product": "Mattermost",
"versions": [
{
"status": "affected",
"version": "9.10.0",
"versionType": "semver",
"lessThanOrEqual": "9.10.2"
},
{
"status": "affected",
"version": "9.11.0",
"versionType": "semver",
"lessThanOrEqual": "9.11.1"
},
{
"status": "affected",
"version": "9.5.0",
"versionType": "semver",
"lessThanOrEqual": "9.5.9"
},
{
"status": "unaffected",
"version": "10.0.0"
},
{
"status": "unaffected",
"version": "9.10.3"
},
{
"status": "unaffected",
"version": "9.11.2"
},
{
"status": "unaffected",
"version": "9.5.10"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2024-10-29T09:15:07.753",
"references": [
{
"url": "https://mattermost.com/security-updates",
"tags": [
"Vendor Advisory"
],
"source": "responsibledisclosure@mattermost.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "responsibledisclosure@mattermost.com",
"description": [
{
"lang": "en",
"value": "CWE-770"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1 and 9.5.x <= 9.5.9 fail to prevent detailed error messages from being displayed in Playbooks which allows an attacker to generate a large response and cause an amplified GraphQL response which in turn could cause the application to crash by sending a specially crafted request to Playbooks."
},
{
"lang": "es",
"value": "Las versiones 9.10.x <= 9.10.2, 9.11.x <= 9.11.1 y 9.5.x <= 9.5.9 de Mattermost no evitan que se muestren mensajes de error detallados en Playbooks, lo que permite a un atacante generar una respuesta grande y causar una respuesta GraphQL amplificada que, a su vez, podría provocar que la aplicación se bloquee al enviar una solicitud especialmente manipulada a Playbooks."
}
],
"lastModified": "2026-06-17T07:57:01.933",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E022FB98-95D6-4F82-9A9F-0C320633E64D",
"versionEndExcluding": "9.5.10",
"versionStartIncluding": "9.5.0"
},
{
"criteria": "cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6E2037E9-B6B2-4764-A5C9-5006DCF34E94",
"versionEndExcluding": "9.10.3",
"versionStartIncluding": "9.10.0"
},
{
"criteria": "cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5F0D9909-E2B9-41B3-93F7-6C666434FE7B",
"versionEndExcluding": "9.11.2",
"versionStartIncluding": "9.11.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "responsibledisclosure@mattermost.com"
}