CVE-2023-3614

Mattermost fails to properly validate a gif image file, allowing an attacker toconsume a significant amount of server resources, making the server unresponsive for an extended period of time bylinking to specially crafted image file.

ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
MattermostCNA
4.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 22%
VendorProductVersion
mattermostmattermost_server
𝑥
< 7.8.7
mattermostmattermost_server
7.9.0 ≤
𝑥
< 7.9.5
mattermostmattermost_server
7.10.0 ≤
𝑥
< 7.10.3
𝑥
= Vulnerable software versions