Mattermost Mobile Apps versions <=2.16.0 fail to validate that the push notifications received for a server actually came from this serve that which allows a malicious server to send push notifications with another server’s diagnostic ID or server URL and have them show up in mobile apps as that server’s push notifications.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-38231 Mattermost Mobile Apps versions <=2.16.0 fail to validate that the push notifications received for a server actually came from this serve that which allows a malicious server to send push notifications with another server’s diagnostic ID or server URL and have them show up in mobile apps as that server’s push notifications.
Fixes

Solution

Update Mattermost Mobile Apps to versions 2.17.0 or higher.


Workaround

No workaround given by the vendor.

References
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2024-08-02T04:26:15.989Z

Reserved: 2024-07-11T14:48:59.897Z

Link: CVE-2024-39767

cve-icon Vulnrichment

Updated: 2024-08-02T04:26:15.989Z

cve-icon NVD

Status : Modified

Published: 2024-07-15T09:15:02.573

Modified: 2024-11-21T09:28:20.950

Link: CVE-2024-39767

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.