Mattermost Mobile fails to limit the maximum number of Markdown elements in a post allowing an attacker to send a post with hundreds of emojis to a channel and freeze the mobile app of users when viewing that particular channel. 

Advisories
Source ID Title
EUVD EUVD EUVD-2023-57835 Mattermost Mobile fails to limit the maximum number of Markdown elements in a post allowing an attacker to send a post with hundreds of emojis to a channel and freeze the mobile app of users when viewing that particular channel. 
Fixes

Solution

Update Mattermost Mobile to versions 2.8.0 or higher.


Workaround

No workaround given by the vendor.

References
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2024-09-05T19:58:49.574Z

Reserved: 2023-10-11T12:14:11.518Z

Link: CVE-2023-5522

cve-icon Vulnrichment

Updated: 2024-08-02T07:59:44.863Z

cve-icon NVD

Status : Modified

Published: 2023-10-17T10:15:10.427

Modified: 2024-11-21T08:41:56.090

Link: CVE-2023-5522

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.