Impact
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to limit decompressed content size and enforce the configured maximum file size in the Boards archive import handler, which allows an authenticated user to cause memory exhaustion or unbounded disk consumption via a crafted .boardarchive file uploaded to the import endpoint. The result is a denial of service that may render the application or its host system unusable until resources are replenished.
Affected Systems
The issue affects Mattermost, specifically versions 11.9.x through 11.9.0, 11.8.x through 11.8.4, 11.7.x through 11.7.7, and 10.11.x through 10.11.22.
Risk and Exploitability
This vulnerability has a CVSS score of 6.5, indicating a moderate level of severity. The EPSS score is < 1%, indicating a very low but nonzero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. An attacker must be authenticated to trigger the vulnerability, but the lack of proper resource limits makes it straightforward to abuse the upload mechanism to exhaust system resources. No public exploit has yet been observed, but the risk is significant for installations that allow ordinary users to import boards.
OpenCVE Enrichment