Description
Mattermost version 7.1.x and earlier fails to sufficiently process a specifically crafted GIF file when it is uploaded while drafting a post, which allows authenticated users to cause resource exhaustion while processing the file, resulting in server-side Denial of Service.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update Mattermost to version v7.2 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-6874 | Mattermost version 7.1.x and earlier fails to sufficiently process a specifically crafted GIF file when it is uploaded while drafting a post, which allows authenticated users to cause resource exhaustion while processing the file, resulting in server-side Denial of Service. |
Github GHSA |
GHSA-m7w4-q5vg-5xfp | Mattermost subject to Denial of Service via upload of special GIF |
References
History
Sat, 07 Dec 2024 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-12-06T23:07:48.369Z
Reserved: 2022-09-21T00:00:00.000Z
Link: CVE-2022-3257
Updated: 2024-08-03T01:07:05.657Z
Status : Modified
Published: 2022-09-23T15:15:13.857
Modified: 2024-11-21T07:19:09.480
Link: CVE-2022-3257
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA