CVE Feed

    Dashboard / CVE / CVE-2021-29453

    CVE-2021-29453

    matrix-media-repo is an open-source multi-domain media repository for Matrix. Versions 1.2.6 and earlier of matrix-media-repo do not properly handle malicious images which are crafted to be small in file size, but large in complexity. A malicious user could upload a relatively small image in terms of file size, using particular image formats, which expands to have extremely large dimensions during the process of thumbnailing. The server can be exhausted of memory in the process of trying to load the whole image into memory for thumbnailing, leading to denial of service. Version 1.2.7 has a fix for the vulnerability.

    Published:Apr 19, 2021
    Last Modified:Nov 21, 2024
    EPS:Apr 19, 2021
    EPSS Score:0.0032
    CVSS Score:5.7

    Affected Products

    Vendor
    Matrix-media-repo Project
    Product
    Matrix-media-repo

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High