First published: Tue Jan 18 2022(Updated: )
Mattermost 6.2 and earlier fails to sufficiently process a specifically crafted GIF file when it is uploaded while drafting a post, which allows authenticated users to cause resource exhaustion while processing the file, resulting in server-side Denial of Service.
Credit: responsibledisclosure@mattermost.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mattermost Mattermost | <=6.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-37865 is a vulnerability in Mattermost 6.2 and earlier that allows authenticated users to cause a server-side Denial of Service by uploading a specially crafted GIF file.
CVE-2021-37865 affects Mattermost versions up to and including 6.2.0, causing resource exhaustion and server-side Denial of Service when an authenticated user uploads a specific GIF file while drafting a post.
CVE-2021-37865 has a severity rating of medium, with a CVSS score of 5.7.
To mitigate CVE-2021-37865, it is recommended to update Mattermost to a version that includes the fix for the vulnerability.
More information about CVE-2021-37865 can be found on the HackerOne report (https://hackerone.com/reports/1428260) and the Mattermost security updates page (https://mattermost.com/security-updates/).