Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9rmc-xf66-rv68

Опубликовано: 10 сент. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

Mattermost version 7.0.x and earlier fails to sufficiently limit the in-memory sizes of concurrently uploaded JPEG images, which allows authenticated users to cause resource exhaustion on specific system configurations, resulting in server-side Denial of Service.

Mattermost version 7.0.x and earlier fails to sufficiently limit the in-memory sizes of concurrently uploaded JPEG images, which allows authenticated users to cause resource exhaustion on specific system configurations, resulting in server-side Denial of Service.

EPSS

Процентиль: 72%
0.00725
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-400
CWE-770

Связанные уязвимости

CVSS3: 3.1
nvd
больше 3 лет назад

Mattermost version 7.0.x and earlier fails to sufficiently limit the in-memory sizes of concurrently uploaded JPEG images, which allows authenticated users to cause resource exhaustion on specific system configurations, resulting in server-side Denial of Service.

CVSS3: 3.1
debian
больше 3 лет назад

Mattermost version 7.0.x and earlier fails to sufficiently limit the i ...

EPSS

Процентиль: 72%
0.00725
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-400
CWE-770