Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-1402


Mattermost fails to check if a custom emoji reaction exists when sending it to a post and to limit the amount of custom emojis allowed to be added in a post, allowing an attacker sending a huge amount of non-existent custom emojis in a post to crash the mobile app of a user seeing the post and to crash the server due to overloading when clients attempt to retrive the aforementioned post. 


Published

2024-02-09T16:15:07.880

Last Modified

2024-11-21T08:50:30.447

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-400
  • Type: Primary
    CWE-400

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application mattermost mattermost_server ≤ 8.1.7 Yes
Application mattermost mattermost_server ≤ 9.1.4 Yes
Application mattermost mattermost_server ≤ 9.2.3 Yes

References