cbcvebase.
CVE-2022-3257
published 2022-09-23

CVE-2022-3257: Mattermost version 7.1.x and earlier fails to sufficiently process a specifically crafted GIF file when it is uploaded while drafting a post, which allows…

PriorityP431medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
1.10%
61.9th percentile
Mattermost version 7.1.x and earlier fails to sufficiently process a specifically crafted GIF file when it is uploaded while drafting a post, which allows authenticated users to cause resource exhaustion while processing the file, resulting in server-side Denial of Service.

Affected

3 ranges
VendorProductVersion rangeFixed in
github.commattermost_mattermost-server_v6>= 7.1.0 < 7.2.07.2.0
mattermostmattermostunspecified – 7.1.x
mattermostmattermost_server< 7.2.07.2.0
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.