GHSA-gwpf-95jc-63rv

Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/06/GHSA-gwpf-95jc-63rv/GHSA-gwpf-95jc-63rv.json
Aliases
  • CVE-2022-1982
Published
2022-06-03T00:00:41Z
Modified
2022-06-17T01:01:48Z
Details

Uncontrolled resource consumption in Mattermost version 6.6.0 and earlier allows an authenticated attacker to crash the server via a crafted SVG attachment on a post.

References

Affected packages

Go / github.com/mattermost/mattermost-server

github.com/mattermost/mattermost-server

Affected ranges

Type
SEMVER
Events
Introduced
6.6.0
Fixed
6.6.1

Affected versions

Go / github.com/mattermost/mattermost-server

github.com/mattermost/mattermost-server

Affected ranges

Type
SEMVER
Events
Introduced
6.5.0
Fixed
6.5.1

Affected versions

Go / github.com/mattermost/mattermost-server

github.com/mattermost/mattermost-server

Affected ranges

Type
SEMVER
Events
Introduced
6.4.0
Fixed
6.4.3

Affected versions

Go / github.com/mattermost/mattermost-server

github.com/mattermost/mattermost-server

Affected ranges

Type
SEMVER
Events
Introduced
5.0.0
Fixed
6.3.8

Affected versions