CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 4.3. Exploitation may require the attacker to be authenticated. It may lead to a denial-of-service condition.
CVE
CVE-2021-37865
Severity
MEDIUM
CVSS
4.3
EPSS
0.90%
Original NVD Description
Mattermost 6.2 and earlier fails to sufficiently process a specifically crafted GIF file when it is uploaded while drafting a post, which allows authenticated users to cause resource exhaustion while processing the file, resulting in server-side Denial of Service.
Related CVEs
Other vulnerabilities affecting the same vendor(s)