PT-2021-18226 · Unknown · Matrix Media Repo

Mr-Zheev

+1

·

Published

2021-04-19

·

Updated

2022-08-03

·

CVE-2021-29453

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: matrix-media-repo versions 1.2.6 and earlier
Description: The issue arises from improper handling of malicious images that are small in file size but large in complexity. A malicious user can upload a small image using specific formats that expands to extremely large dimensions during thumbnailing, causing the server to exhaust its memory and leading to denial of service.
Recommendations: For versions 1.2.6 and earlier, update to version 1.2.7 to resolve the issue.

Fix

Allocation of Resources Without Limits

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2021-29453
GHSA-J889-H476-HH9H

Affected Products

Matrix Media Repo