CVE-2022-4019 – Authenticated user could send multiple requests containing a large payload to a Playbooks API and can crash a Mattermost server
https://notcve.org/view.php?id=CVE-2022-4019
A denial-of-service vulnerability in the Mattermost Playbooks plugin allows an authenticated user to crash the server via multiple large requests to one of the Playbooks API endpoints. Una vulnerabilidad de Denegación de Servicio (DoS) en el complemento Mattermost Playbooks permite que un usuario autenticado bloquee el servidor a través de múltiples solicitudes grandes a uno de los endpoints de la API de Playbooks. • https://hackerone.com/reports/1685979 https://mattermost.com/security-updates • CWE-770: Allocation of Resources Without Limits or Throttling •
CVE-2022-3257 – Server-side Denial of Service while processing a specifically crafted GIF file
https://notcve.org/view.php?id=CVE-2022-3257
Mattermost version 7.1.x and earlier fails to sufficiently process a specifically crafted GIF file when it is uploaded while drafting a post, which allows authenticated users to cause resource exhaustion while processing the file, resulting in server-side Denial of Service. Mattermost versión 7.1.x y anteriores, no procesan suficientemente un archivo GIF específicamente diseñado cuando es descargado mientras es redactada una publicación, lo que permite a usuarios autenticados causar el agotamiento de los recursos mientras es procesado el archivo, resultando en una Denegación de Servicio del lado del servidor. • https://hackerone.com/reports/1620170 https://mattermost.com/security-updates • CWE-400: Uncontrolled Resource Consumption CWE-434: Unrestricted Upload of File with Dangerous Type •
CVE-2022-3147 – Server-side Denial of Service while processing a specifically crafted JPEG file
https://notcve.org/view.php?id=CVE-2022-3147
Mattermost version 7.0.x and earlier fails to sufficiently limit the in-memory sizes of concurrently uploaded JPEG images, which allows authenticated users to cause resource exhaustion on specific system configurations, resulting in server-side Denial of Service. Mattermost versiones 7.0.x y anteriores, no limitan suficientemente los tamaños en memoria de las imágenes JPEG cargadas simultáneamente, lo que permite a usuarios autenticados causar el agotamiento de los recursos en configuraciones específicas del sistema, resultando en una Denegación de Servicio del lado del servidor • https://hackerone.com/reports/1549513 https://mattermost.com/security-updates • CWE-400: Uncontrolled Resource Consumption CWE-770: Allocation of Resources Without Limits or Throttling •
CVE-2022-2408 – Guest accounts can list all public channels
https://notcve.org/view.php?id=CVE-2022-2408
The Guest account feature in Mattermost version 6.7.0 and earlier fails to properly restrict the permissions, which allows a guest user to fetch a list of all public channels in the team, in spite of not being part of those channels. La función de cuenta de invitado en Mattermost versiones 6.7.0 y anteriores no restringe apropiadamente los permisos, lo que permite a un usuario invitado conseguir una lista de todos los canales públicos del equipo, a pesar de no formar parte de esos canales • https://mattermost.com/security-updates • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-863: Incorrect Authorization •
CVE-2022-2406 – Malicious imports can lead to Denial of Service
https://notcve.org/view.php?id=CVE-2022-2406
The legacy Slack import feature in Mattermost version 6.7.0 and earlier fails to properly limit the sizes of imported files, which allows an authenticated attacker to crash the server by importing large files via the Slack import REST API. La función de importación de Slack heredada en Mattermost versiones 6.7.0 y anteriores, no limita apropiadamente el tamaño de los archivos importados, lo que permite a un atacante autenticado bloquear el servidor importando archivos grandes por medio de la API REST de importación de Slack • https://mattermost.com/security-updates • CWE-400: Uncontrolled Resource Consumption CWE-770: Allocation of Resources Without Limits or Throttling •