Mattermost fails to check if a custom emoji reaction exists when sending it to a post and to limit the amount of custom emojis allowed to be added in a post, allowing an attacker sending a huge amount of non-existent custom emojis in a post to crash the mobile app of a user seeing the post and to crash the server due to overloading when clients attempt to retrive the aforementioned post.
2024-02-09T16:15:07.880
2024-11-21T08:50:30.447
Modified
CVSSv3.1: 4.3 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mattermost | mattermost_server | ≤ 8.1.7 | Yes |
Application | mattermost | mattermost_server | ≤ 9.1.4 | Yes |
Application | mattermost | mattermost_server | ≤ 9.2.3 | Yes |