Mattermost fails to properly validate the length of the emoji value in the custom user status, allowing an attacker to send multiple times a very long string as an emoji value causing high resource consumption and possibly crashing the server.
2024-02-29T08:15:47.640
2025-01-10T15:38:05.187
Analyzed
CVSSv3.1: 4.3 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mattermost | mattermost_server | < 8.1.8 | Yes |
Application | mattermost | mattermost_server | < 9.1.5 | Yes |
Application | mattermost | mattermost_server | < 9.2.4 | Yes |