Impact
Mattermost versions 11.9.x through 11.9.0, 11.8.x through 11.8.4, 11.7.x through 11.7.7, and 10.11.x through 10.11.22 fail to properly limit resource consumption when processing certain user-supplied input, allowing an authenticated user to cause a denial of service.
Affected Systems
The issue affects Mattermost, specifically versions 11.9.x through 11.9.0, 11.8.x through 11.8.4, 11.7.x through 11.7.7, and 10.11.x through 10.11.22.
Risk and Exploitability
This vulnerability has a CVSS score of 6.5, indicating a moderate level of severity. The EPSS score is not available, so the exploit probability is currently unknown, and the vulnerability is not listed in the CISA KEV catalog. An attacker must be authenticated to trigger the vulnerability, but the lack of proper resource limits makes it straightforward to abuse the upload mechanism to exhaust system resources. No public exploit has yet been observed, but the risk is significant for installations that allow ordinary users to import boards.
OpenCVE Enrichment