CVE-2019-20860

An issue was discovered in Mattermost Server before 5.14.0, 5.13.3, 5.12.6, and 5.9.4. It allows remote attackers to cause a denial of service (application hang) via a crafted SVG document.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.5 MEDIUM
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 47%
VendorProductVersion
mattermostmattermost_server
𝑥
< 5.9.4
mattermostmattermost_server
5.12.0 ≤
𝑥
< 5.12.6
mattermostmattermost_server
5.13.0 ≤
𝑥
< 5.13.3
mattermostmattermost_server
5.14.0:rc1
mattermostmattermost_server
5.14.0:rc2
mattermostmattermost_server
5.14.0:rc3
mattermostmattermost_server
5.14.0:rc4
mattermostmattermost_server
5.14.0:rc5
𝑥
= Vulnerable software versions