First published: Wed Apr 13 2022(Updated: )
The image proxy component in Mattermost version 6.4.1 and earlier allocates memory for multiple copies of a proxied image, which allows an authenticated attacker to crash the server via links to very large image files.
Credit: responsibledisclosure@mattermost.com responsibledisclosure@mattermost.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mattermost Mattermost Server | >=5.37.0<5.37.9 | |
Mattermost Mattermost Server | >=6.2.0<6.2.5 | |
Mattermost Mattermost Server | >=6.3.0<6.3.5 | |
Mattermost Mattermost Server | >=6.4.0<6.4.2 | |
go/github.com/mattermost/mattermost-server/v6 | <6.4.2 | 6.4.2 |
Upgrade to Mattermost version 6.4.2, 6.3.5, 6.2.5, or 5.37.9.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Mattermost issue is CVE-2022-1337.
The severity level of CVE-2022-1337 is medium.
The image proxy component in Mattermost version 6.4.1 and earlier allocates memory for multiple copies of a proxied image, which allows an authenticated attacker to crash the server via links to very large image files.
Mattermost Server versions 5.37.0 to 5.37.9, 6.2.0 to 6.2.5, 6.3.0 to 6.3.5, and 6.4.0 to 6.4.2 are affected by CVE-2022-1337.
To fix CVE-2022-1337, you should update Mattermost Server to version 6.4.2 or later.