CVE-2022-1982: A crafted SVG attachment can crash a Mattermost server
Published Jun 2, 2022
·Updated
Uncontrolled resource consumption in Mattermost version 6.6.0 and earlier allows an authenticated attacker to crash the server via a crafted SVG attachment on a post.
Affected Software
4 affected components
Mattermost Mattermost Server>=5.0.0<6.3.8
Mattermost Mattermost Server>=6.4.0<6.4.3
Mattermost Mattermost Server=6.5.0
Mattermost Mattermost Server=6.6.0
Event History
Jun 2, 2022
CVE Published
via MITRE·05:03 PM
Data Sourced
via MITRE·05:03 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-1982?
The severity of CVE-2022-1982 is medium.
2
How does CVE-2022-1982 affect Mattermost?
CVE-2022-1982 affects Mattermost versions 6.6.0 and earlier.
3
How can an attacker exploit CVE-2022-1982?
An attacker can exploit CVE-2022-1982 by sending a crafted SVG attachment on a post to crash the Mattermost server.
4
Is there a fix for CVE-2022-1982?
Yes, an update to Mattermost version 6.6.1 or later fixes CVE-2022-1982.
5
Where can I find more information about CVE-2022-1982?
You can find more information about CVE-2022-1982 at the following link: [https://mattermost.com/security-updates/](https://mattermost.com/security-updates/).