PT-2024-18013 · Mattermost · Mattermost

Gian Klug

·

Published

2024-02-09

·

Updated

2024-06-28

·

CVE-2024-1402

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Mattermost versions prior to v8.1.8
Description The issue arises from the failure to check if a custom emoji reaction exists when sending it to a post and to limit the amount of custom emojis allowed to be added in a post. This allows an attacker to send a huge amount of non-existent custom emojis in a post, potentially crashing the mobile app of a user seeing the post and overloading the server when clients attempt to retrieve the post. This results in Uncontrolled Resource Consumption.
Recommendations For Mattermost versions prior to v8.1.8, update to version v8.1.8 or later to resolve the issue. As a temporary workaround, consider restricting the amount of custom emojis that can be added to a post to prevent overloading. Additionally, limiting the number of reactions fetched for a post can help mitigate the risk of crashing the mobile app or server.

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-MATTERMOST-2024-1402
CVE-2024-1402
GHSA-32H7-7J94-8FC2
GO-2024-2541

Affected Products

Mattermost