CVE-2022-2406
Summary
| CVE | CVE-2022-2406 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-07-14 18:15:00 UTC |
| Updated | 2023-06-30 18:49:00 UTC |
| Description | The legacy Slack import feature in Mattermost version 6.7.0 and earlier fails to properly limit the sizes of imported files, which allows an authenticated attacker to crash the server by importing large files via the Slack import REST API. |
Risk And Classification
Problem Types: CWE-770
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mattermost | Mattermost | 6.6.0 | All | All | All |
| Application | Mattermost | Mattermost | 6.6.1 | All | All | All |
| Application | Mattermost | Mattermost | 6.7.0 | All | All | All |
| Application | Mattermost | Mattermost | All | All | All | All |
| Application | Mattermost | Mattermost | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Updates - Mattermost Open Source Collaboration Platform | MISC | mattermost.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Thanks to Juho Nurminen for contributing to this improvement under the Mattermost responsible disclosure policy.
There are currently no legacy QID mappings associated with this CVE.