VYPR
Moderate severityNVD Advisory· Published Jun 2, 2022· Updated Dec 6, 2024

A crafted SVG attachment can crash a Mattermost server

CVE-2022-1982

Description

Uncontrolled resource consumption in Mattermost version 6.6.0 and earlier allows an authenticated attacker to crash the server via a crafted SVG attachment on a post.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/mattermost/mattermost-serverGo
>= 6.6.0, < 6.6.16.6.1
github.com/mattermost/mattermost-serverGo
>= 6.5.0, < 6.5.16.5.1
github.com/mattermost/mattermost-serverGo
>= 6.4.0, < 6.4.36.4.3
github.com/mattermost/mattermost-serverGo
>= 5.0.0, < 6.3.86.3.8

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.