endpointlabs / VulnerableDotNetCore3Project

.Net Core 3.0
0 stars 0 forks source link

Uncontrolled Resource Consumption in Mattermost server (CWE-400) #42

Open cbilgin23 opened 1 year ago

cbilgin23 commented 1 year ago

Due Date: 2022-09-29

A medium severity vulnerability has been discovered in your project.

Project Name: test

Scanner Name: dependabot

Cwe ID: 400

Cwe Name: Uncontrolled Resource Consumption (Resource Exhaustion)

Cwe Link: https://cwe.mitre.org/data/definitions/400.html

File: go.sum

Packages:

References:

Training(Secure Code Warrior):



Tool Description: Uncontrolled resource consumption in Mattermost version 6.6.0 and earlier allows an authenticated attacker to crash the server via a crafted SVG attachment on a post.

Kondukto Link: http://80.kondukto.local/projects/6331ad74ef14f4953e572991/vulns/appsec?page=1&perPage=15&id=in:63359eddde3f4040f62a1569