Description
The image proxy component in Mattermost version 6.4.1 and earlier allocates memory for multiple copies of a proxied image, which allows an authenticated attacker to crash the server via links to very large image files.
No analysis available yet.
Remediation
Vendor Solution
Upgrade to Mattermost version 6.4.2, 6.3.5, 6.2.5, or 5.37.9.
Vendor Workaround
Disable the image proxy or use an external proxy.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-1715 | The image proxy component in Mattermost version 6.4.1 and earlier allocates memory for multiple copies of a proxied image, which allows an authenticated attacker to crash the server via links to very large image files. |
Github GHSA |
GHSA-f37q-q7p2-ccfc | Resource exhaustion in Mattermost |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates/ |
|
History
Fri, 06 Dec 2024 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-12-06T23:10:06.768Z
Reserved: 2022-04-13T00:00:00.000Z
Link: CVE-2022-1337
Updated: 2024-08-03T00:03:05.454Z
Status : Modified
Published: 2022-04-13T18:15:09.893
Modified: 2024-11-21T06:40:31.097
Link: CVE-2022-1337
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA