Description
Mattermost fails to properly validate the length of the emoji value in the custom user status, allowing an attacker to send multiple times a very long string as an emoji value causing high resource consumption and possibly crashing the server.
No analysis available yet.
Remediation
Vendor Solution
Update Mattermost Server to versions 9.4.0, 9.3.1, 9.2.5, 8.1.9 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0537 | Mattermost fails to properly validate the length of the emoji value in the custom user status, allowing an attacker to send multiple times a very long string as an emoji value causing high resource consumption and possibly crashing the server. |
Github GHSA |
GHSA-6mx3-9qfh-77gj | Mattermost denial of service through long emoji value |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
Fri, 10 Jan 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost
Mattermost mattermost Server |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mattermost
Mattermost mattermost Server |
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-08-01T23:36:21.288Z
Reserved: 2024-02-26T08:14:42.970Z
Link: CVE-2024-24988
Updated: 2024-08-01T23:36:21.288Z
Status : Analyzed
Published: 2024-02-29T08:15:47.640
Modified: 2025-01-10T15:38:05.187
Link: CVE-2024-24988
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA