PT-2022-20747 · Mattermost · Mattermost
Philippe Antoine
·
Published
2022-09-09
·
Updated
2024-03-06
·
CVE-2022-3147
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Mattermost versions 7.0.x and earlier
Description
The issue allows authenticated users to cause resource exhaustion on specific system configurations, resulting in server-side Denial of Service, due to insufficient limitation of the in-memory sizes of concurrently uploaded JPEG images.
Recommendations
For Mattermost versions 7.0.x and earlier, consider restricting the upload of JPEG images or limiting the concurrent upload capability to prevent resource exhaustion until a fix is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Resource Exhaustion
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mattermost