Mattermost subject to Denial of Service via upload of special GIF
Moderate severity
GitHub Reviewed
Published
Sep 25, 2022
to the GitHub Advisory Database
•
Updated Mar 27, 2023
Package
Affected versions
>= 7.1.0, < 7.2.0
Patched versions
7.2.0
Description
Published by the National Vulnerability Database
Sep 23, 2022
Published to the GitHub Advisory Database
Sep 25, 2022
Reviewed
Sep 28, 2022
Last updated
Mar 27, 2023
Mattermost version 7.1.x and earlier fails to sufficiently process a specifically crafted GIF file when it is uploaded while drafting a post, which allows authenticated users to cause resource exhaustion while processing the file, resulting in server-side Denial of Service.
References