Mattermost Mobile Apps versions <=2.16.0 fail to validate that the push notifications received for a server actually came from this serve that which allows a malicious server to send push notifications with another server’s diagnostic ID or server URL and have them show up in mobile apps as that server’s push notifications.
References
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published: 2024-07-15T08:43:10.236Z

Updated: 2024-08-02T04:26:15.989Z

Reserved: 2024-07-11T14:48:59.897Z

Link: CVE-2024-39767

cve-icon Vulnrichment

Updated: 2024-08-02T04:26:15.989Z

cve-icon NVD

Status : Analyzed

Published: 2024-07-15T09:15:02.573

Modified: 2024-07-16T18:04:02.993

Link: CVE-2024-39767

cve-icon Redhat

No data.