Impact
Mattermost versions up to 11.9.0, 11.8.4, 11.7.7, and 10.11.22 improperly enforce limits on concurrent file processing and handling of failed files. A user with permission to upload files can create more worker goroutines than intended, causing the extraction pool to fill and preventing other files from being indexed. The primary effect is a denial of service that blocks indexing for legitimate content, impacting availability for all users.
Affected Systems
The affected product is Mattermost. The vulnerable releases are 10.11.x versions up to and including 10.11.22, 11.7.x up to and including 11.7.7, 11.8.x up to and including 11.8.4, and 11.9.x up to and including 11.9.0. All subsequent releases above 10.11.23, 11.7.8, 11.8.5, 11.9.1, and 11.10.0 contain the fix.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers must be authenticated members with file upload rights; typical exploitation involves submitting large or repeated files to exhaust the extraction pool. While it does not lead to code execution, the denial of service could disrupt collaboration services.
OpenCVE Enrichment