First published: Fri Sep 09 2022(Updated: )
Mattermost version 7.0.x and earlier fails to sufficiently limit the in-memory sizes of concurrently uploaded JPEG images, which allows authenticated users to cause resource exhaustion on specific system configurations, resulting in server-side Denial of Service.
Credit: responsibledisclosure@mattermost.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mattermost | <7.1.0 |
Update Mattermost to version v7.1 or higher.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-3147 is a vulnerability in Mattermost version 7.0.x and earlier that allows authenticated users to cause resource exhaustion resulting in server-side Denial of Service.
Mattermost version 7.0.x and earlier fails to sufficiently limit the in-memory sizes of concurrently uploaded JPEG images.
The vulnerability can cause resource exhaustion on specific system configurations, resulting in server-side Denial of Service.
The severity of CVE-2022-3147 is medium with a CVSS score of 6.5.
To fix CVE-2022-3147, upgrade to Mattermost version 7.1.0 or later.