CVE-2023-3614Uncontrolled Resource Consumption in Server

Severity
3.3LOWNVD
CNA4.3
EPSS
0.1%
top 74.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 17

Description

Mattermost fails to properly validate a gif image file, allowing an attacker to consume a significant amount of server resources, making the server unresponsive for an extended period of time by linking to specially crafted image file.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:LExploitability: 1.8 | Impact: 1.4

Affected Packages2 packages

NVDmattermost/mattermost_server7.9.07.9.5+2
CVEListV5mattermost/mattermost7.8.6+2

🔴Vulnerability Details

2
GHSA
GHSA-p6xc-cw4f-5cmp: Mattermost fails to properly validate a gif image file, allowing an attacker to consume a significant amount of server resources, making the server un2023-07-17
CVEList
Denial of Service via specially crafted gif image2023-07-17
CVE-2023-3614 — Uncontrolled Resource Consumption | cvebase