Mattermost
cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*
- >= 11.5.0, <= 11.5.1
- >= 10.11.0, <= 10.11.13
- >= 11.4.0, <= 11.4.3
A denial-of-service vulnerability has been identified in Mattermost versions 11.5.x through 11.5.1, 10.11.x through 10.11.13, and 11.4.x through 11.4.3. The issue arises because these versions do not properly validate the structure of 7zip archives before processing them. This flaw allows an authenticated attacker to upload a specially crafted 7zip file containing excessive folder declarations, leading to server memory exhaustion and causing a denial-of-service condition.
Exploitation of this vulnerability leads to server memory exhaustion, causing a denial-of-service condition.
Users can upgrade to Mattermost versions 11.7.0, 11.6.1, or 10.11.15 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.