Launch Week Day 1: Announcing Security Design Review
MEDIUM 6.5 Go

Resource exhaustion in Mattermost

GHSA-f37q-q7p2-ccfc · BIT-mattermost-2022-1337 · CVE-2022-1337 · GO-2022-0595

Published · Modified

Description

The image proxy component in Mattermost version 6.4.1 and earlier allocates memory for multiple copies of a proxied image, which allows an authenticated attacker to crash the server via links to very large image files.

Ready to move

Start Securing

Free, no credit card | First findings in minutes