5.5
CVSS V3
Status
Impact
The issue regarding disintegration/imaging v1.6.2 where the index of the scan function in scanner.go can go out of bounds has an open PR https://github.com/disintegration/imaging/issues/165 but no implanted fix yet
Status
Impact
This vulnerability relates to one of mattermost's dependencies - 'github.com/disintegration/imaging'. Mattermost is running the most recent version - v1.6.2, which still contains this vulnerability.
Status