CVE-2022-1337Uncontrolled Resource Consumption in Mattermost

Severity
6.5MEDIUMNVD
CNA4.3
EPSS
0.4%
top 37.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 13
Latest updateAug 21

Description

The image proxy component in Mattermost version 6.4.1 and earlier allocates memory for multiple copies of a proxied image, which allows an authenticated attacker to crash the server via links to very large image files.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages3 packages

NVDmattermost/mattermost_server5.37.05.37.9+3
CVEListV5mattermost/mattermost6.46.4.2+3

🔴Vulnerability Details

4
OSV
Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server2024-08-21
OSV
Resource exhaustion in Mattermost2022-04-14
GHSA
Resource exhaustion in Mattermost2022-04-14
CVEList
OOM DoS in Mattermost image proxy2022-04-13

💥Exploits & PoCs

2
Exploit-DB
PnPSCADA v2.x - Unauthenticated PostgreSQL Injection2023-05-23
Exploit-DB
TP-Link Tapo c200 1.1.15 - Remote Code Execution (RCE)2022-09-23
CVE-2022-1337 — Uncontrolled Resource Consumption | cvebase