CVE-2024-1402
09.02.2024, 16:15
Mattermost fails to check if a custom emoji reaction exists when sending it to a post and to limit the amount of custom emojis allowed to be added in a post, allowing an attacker sending a huge amount of non-existent custom emojis in a post to crash the mobile app of a user seeing the post and to crash the server due to overloading when clients attempt to retrive the aforementioned post.Enginsight
Vendor | Product | Version |
---|---|---|
mattermost | mattermost_server | 𝑥 ≤ 8.1.7 |
mattermost | mattermost_server | 9.0.0 ≤ 𝑥 ≤ 9.1.4 |
mattermost | mattermost_server | 9.2.0 ≤ 𝑥 ≤ 9.2.3 |
𝑥
= Vulnerable software versions