Description
Mattermost versions 9.6.0, 9.5.x before 9.5.3, 9.4.x before 9.4.5, and 8.1.x before 8.1.12 fail to handle JSON parsing errors in custom status values, which allows an authenticated attacker to crash other users' web clients via a malformed custom status.
No analysis available yet.
Remediation
Vendor Solution
Update Mattermost Server to versions 9.7.0, 9.6.1, 9.5.3, 9.4.5, 8.1.12 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-1158 | Mattermost versions 9.6.0, 9.5.x before 9.5.3, 9.4.x before 9.4.5, and 8.1.x before 8.1.12 fail to handle JSON parsing errors in custom status values, which allows an authenticated attacker to crash other users' web clients via a malformed custom status. |
Github GHSA |
GHSA-8f99-g2pj-x8w3 | Mattermost crashes web clients via a malformed custom status |
References
History
Mon, 12 May 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost
Mattermost mattermost Server |
|
| CPEs | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mattermost
Mattermost mattermost Server |
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-08-01T20:33:52.520Z
Reserved: 2024-04-25T14:04:51.237Z
Link: CVE-2024-4182
Updated: 2024-08-01T20:33:52.520Z
Status : Analyzed
Published: 2024-04-26T09:15:12.523
Modified: 2025-05-12T13:41:16.170
Link: CVE-2024-4182
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA