CVE-2022-1337: OOM DoS in Mattermost image proxy
The image proxy component in Mattermost version 6.4.1 and earlier allocates memory for multiple copies of a proxied image, which allows an authenticated attacker to crash the server via links to very large image files.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this Mattermost issue?
The vulnerability ID for this Mattermost issue is CVE-2022-1337.
What is the severity level of CVE-2022-1337?
The severity level of CVE-2022-1337 is medium.
How does the image proxy component in Mattermost version 6.4.1 and earlier lead to the vulnerability?
The image proxy component in Mattermost version 6.4.1 and earlier allocates memory for multiple copies of a proxied image, which allows an authenticated attacker to crash the server via links to very large image files.
Which versions of Mattermost Server are affected by CVE-2022-1337?
Mattermost Server versions 5.37.0 to 5.37.9, 6.2.0 to 6.2.5, 6.3.0 to 6.3.5, and 6.4.0 to 6.4.2 are affected by CVE-2022-1337.
How can I fix CVE-2022-1337?
To fix CVE-2022-1337, you should update Mattermost Server to version 6.4.2 or later.