PT-2021-24341 · Mattermost · Mattermost

Agniva De

·

Published

2021-11-08

·

Updated

2024-08-21

·

CVE-2022-1337

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Mattermost versions 6.4.1 and earlier
Description: The issue is related to the image proxy component, which can lead to resource exhaustion. An authenticated attacker can cause the server to crash by linking to very large image files, resulting in memory allocation for multiple copies of the proxied image.
Recommendations: For Mattermost versions 6.4.1 and earlier, consider disabling the image proxy component as a temporary workaround until a patch is available. Restrict access to large image files to minimize the risk of exploitation.

Fix

Resource Exhaustion

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

BIT-MATTERMOST-2022-1337
CVE-2022-1337
GHSA-F37Q-Q7P2-CCFC
GO-2022-0595

Affected Products

Mattermost