endpointlabs / VulnerableDotNetCore3Project

.Net Core 3.0
0 stars 0 forks source link

CVE-2022-1982 | github.com/mattermost/mattermost-server:v5.11.1+incompatible (CWE-400) #38

Open cbilgin23 opened 2 years ago

cbilgin23 commented 2 years ago

Due Date: 2022-09-26

A medium severity vulnerability has been discovered in your project.

Project Name: test

Scanner Name: dependabot

Cwe ID: 400

Cwe Name: Uncontrolled Resource Consumption (Resource Exhaustion)

Cwe Link: https://cwe.mitre.org/data/definitions/400.html

File: go.sum

Packages:

References:

Training(Secure Code Warrior):



Tool Description: Summary: Uncontrolled Resource Consumption in Mattermost server. Description: Uncontrolled resource consumption in Mattermost version 6.6.0 and earlier allows an authenticated attacker to crash the server via a crafted SVG attachment on a post.

Custom Description: test

Kondukto Link: http://80.kondukto.local/projects/633187358347f9f0ec5b40e9/vulns/appsec?page=1&perPage=15&id=in:6331904a5d406296cad52f9c