Description
Mattermost Mobile Apps versions <=2.16.0 fail to protect against abuse of a globally shared MathJax state which allows an attacker to change the contents of a LateX post, by creating another post with specific macro definitions.
Published: 2024-07-15
Score: 2.6 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Update Mattermost Mobile Apps to versions 2.17.0 or higher.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-34471 Mattermost Mobile Apps versions <=2.16.0 fail to protect against abuse of a globally shared MathJax state which allows an attacker to change the contents of a LateX post, by creating another post with specific macro definitions.
References
History

No history.

Subscriptions

Mattermost Mattermost Mobile
cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2024-08-02T02:27:52.391Z

Reserved: 2024-07-11T14:48:59.891Z

Link: CVE-2024-32945

cve-icon Vulnrichment

Updated: 2024-08-02T02:27:52.391Z

cve-icon NVD

Status : Modified

Published: 2024-07-15T09:15:02.260

Modified: 2024-11-21T09:16:05.340

Link: CVE-2024-32945

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses