Description
Mattermost Mobile Apps versions <=2.16.0 fail to validate that the push notifications received for a server actually came from this serve that which allows a malicious server to send push notifications with another server’s diagnostic ID or server URL and have them show up in mobile apps as that server’s push notifications.
No analysis available yet.
Remediation
Vendor Solution
Update Mattermost Mobile Apps to versions 2.17.0 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-38231 | Mattermost Mobile Apps versions <=2.16.0 fail to validate that the push notifications received for a server actually came from this serve that which allows a malicious server to send push notifications with another server’s diagnostic ID or server URL and have them show up in mobile apps as that server’s push notifications. |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
No history.
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-08-02T04:26:15.989Z
Reserved: 2024-07-11T14:48:59.897Z
Link: CVE-2024-39767
Updated: 2024-08-02T04:26:15.989Z
Status : Modified
Published: 2024-07-15T09:15:02.573
Modified: 2024-11-21T09:28:20.950
Link: CVE-2024-39767
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD