First published: Thu Jun 02 2022(Updated: )
Uncontrolled resource consumption in Mattermost version 6.6.0 and earlier allows an authenticated attacker to crash the server via a crafted SVG attachment on a post.
Credit: responsibledisclosure@mattermost.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mattermost Mattermost Server | >=5.0.0<6.3.8 | |
Mattermost Mattermost Server | >=6.4.0<6.4.3 | |
Mattermost Mattermost Server | =6.5.0 | |
Mattermost Mattermost Server | =6.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-1982 is medium.
CVE-2022-1982 affects Mattermost versions 6.6.0 and earlier.
An attacker can exploit CVE-2022-1982 by sending a crafted SVG attachment on a post to crash the Mattermost server.
Yes, an update to Mattermost version 6.6.1 or later fixes CVE-2022-1982.
You can find more information about CVE-2022-1982 at the following link: [https://mattermost.com/security-updates/](https://mattermost.com/security-updates/).