Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-37865

Опубликовано: 18 янв. 2022
Источник: nvd
CVSS3: 4.3
CVSS3: 5.7
CVSS2: 3.5
EPSS Низкий

Описание

Mattermost 6.2 and earlier fails to sufficiently process a specifically crafted GIF file when it is uploaded while drafting a post, which allows authenticated users to cause resource exhaustion while processing the file, resulting in server-side Denial of Service.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*:*
Версия до 6.2.0 (включая)

EPSS

Процентиль: 58%
0.0037
Низкий

4.3 Medium

CVSS3

5.7 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-400
CWE-400

Связанные уязвимости

CVSS3: 4.3
debian
больше 3 лет назад

Mattermost 6.2 and earlier fails to sufficiently process a specificall ...

github
больше 3 лет назад

Mattermost 6.2 and earlier fails to sufficiently process a specifically crafted GIF file when it is uploaded while drafting a post, which allows authenticated users to cause resource exhaustion while processing the file, resulting in server-side Denial of Service.

EPSS

Процентиль: 58%
0.0037
Низкий

4.3 Medium

CVSS3

5.7 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-400
CWE-400