Mattermost versions 9.6.0, 9.5.x before 9.5.3, 9.4.x before 9.4.5, and 8.1.x before 8.1.12 fail to handle JSON parsing errors in custom status values, which allows an authenticated attacker to crash other users' web clients via a malformed custom status.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: Mattermost
Published: 2024-04-26T08:25:37.093Z
Updated: 2024-08-01T20:33:52.520Z
Reserved: 2024-04-25T14:04:51.237Z
Link: CVE-2024-4182
Vulnrichment
Updated: 2024-08-01T20:33:52.520Z
NVD
Status : Awaiting Analysis
Published: 2024-04-26T09:15:12.523
Modified: 2024-04-26T12:58:17.720
Link: CVE-2024-4182
Redhat