Mattermost versions 9.6.0, 9.5.x before 9.5.3, 9.4.x before 9.4.5, and 8.1.x before 8.1.12 fail to handle JSON parsing errors in custom status values, which allows an authenticated attacker to crash other users' web clients via a malformed custom status.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2024-1158 | Mattermost versions 9.6.0, 9.5.x before 9.5.3, 9.4.x before 9.4.5, and 8.1.x before 8.1.12 fail to handle JSON parsing errors in custom status values, which allows an authenticated attacker to crash other users' web clients via a malformed custom status. |
![]() |
GHSA-8f99-g2pj-x8w3 | Mattermost crashes web clients via a malformed custom status |
Fixes
Solution
Update Mattermost Server to versions 9.7.0, 9.6.1, 9.5.3, 9.4.5, 8.1.12 or higher.
Workaround
No workaround given by the vendor.
References
History
Mon, 12 May 2025 14:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Mattermost
Mattermost mattermost Server |
|
CPEs | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* | |
Vendors & Products |
Mattermost
Mattermost mattermost Server |

Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-08-01T20:33:52.520Z
Reserved: 2024-04-25T14:04:51.237Z
Link: CVE-2024-4182

Updated: 2024-08-01T20:33:52.520Z

Status : Analyzed
Published: 2024-04-26T09:15:12.523
Modified: 2025-05-12T13:41:16.170
Link: CVE-2024-4182


No data.