Description
Mattermost Mobile fails to limit the maximum number of Markdown elements in a post allowing an attacker to send a post with hundreds of emojis to a channel and freeze the mobile app of users when viewing that particular channel. 

Published: 2023-10-17
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Update Mattermost Mobile to versions 2.8.0 or higher.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-57835 Mattermost Mobile fails to limit the maximum number of Markdown elements in a post allowing an attacker to send a post with hundreds of emojis to a channel and freeze the mobile app of users when viewing that particular channel. 
References
History

No history.

Subscriptions

Mattermost Mattermost
cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2024-09-05T19:58:49.574Z

Reserved: 2023-10-11T12:14:11.518Z

Link: CVE-2023-5522

cve-icon Vulnrichment

Updated: 2024-08-02T07:59:44.863Z

cve-icon NVD

Status : Modified

Published: 2023-10-17T10:15:10.427

Modified: 2024-11-21T08:41:56.090

Link: CVE-2023-5522

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses