Mattermost Mobile Apps versions <=2.16.0 fail to protect against abuse of a globally shared MathJax state which allows an attacker to change the contents of a LateX post, by creating another post with specific macro definitions.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-34471 Mattermost Mobile Apps versions <=2.16.0 fail to protect against abuse of a globally shared MathJax state which allows an attacker to change the contents of a LateX post, by creating another post with specific macro definitions.
Fixes

Solution

Update Mattermost Mobile Apps to versions 2.17.0 or higher.


Workaround

No workaround given by the vendor.

References
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2024-08-02T02:27:52.391Z

Reserved: 2024-07-11T14:48:59.891Z

Link: CVE-2024-32945

cve-icon Vulnrichment

Updated: 2024-08-02T02:27:52.391Z

cve-icon NVD

Status : Modified

Published: 2024-07-15T09:15:02.260

Modified: 2024-11-21T09:16:05.340

Link: CVE-2024-32945

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.