Description
Mattermost fails to check if a custom emoji reaction exists when sending it to a post and to limit the amount of custom emojis allowed to be added in a post, allowing an attacker sending a huge amount of non-existent custom emojis in a post to crash the mobile app of a user seeing the post and to crash the server due to overloading when clients attempt to retrive the aforementioned post.
No analysis available yet.
Remediation
Vendor Solution
Update Mattermost Server to versions 9.3.0, 9.2.4, 9.1.5, 8.1.8 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0474 | Mattermost vulnerable to denial of service via large number of emoji reactions |
Github GHSA |
GHSA-32h7-7j94-8fc2 | Mattermost vulnerable to denial of service via large number of emoji reactions |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
No history.
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-08-01T18:40:20.579Z
Reserved: 2024-02-09T14:53:28.621Z
Link: CVE-2024-1402
Updated: 2024-08-01T18:40:20.579Z
Status : Modified
Published: 2024-02-09T16:15:07.880
Modified: 2024-11-21T08:50:30.447
Link: CVE-2024-1402
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA