CVE-2022-2406

The legacy Slack import feature in Mattermost version 6.7.0 and earlier fails to properly limit the sizes of imported files, which allows an authenticated attacker to crash the server by importing large files via the Slack import REST API.
References
Link Resource
https://mattermost.com/security-updates/ Vendor Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost:6.6.1:*:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost:6.6.0:*:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost:6.7.0:*:*:*:*:*:*:*

Information

Published : 2022-07-14 11:15

Updated : 2022-07-25 11:08


NVD link : CVE-2022-2406

Mitre link : CVE-2022-2406


JSON object : View

CWE
CWE-400

Uncontrolled Resource Consumption

Advertisement

dedicated server usa

Products Affected

mattermost

  • mattermost