PT-2024-20683 · Mattermost · Mattermost Mobile

Gian Klug

·

Published

2024-03-15

·

Updated

2025-01-21

·

CVE-2024-24975

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Mattermost Mobile versions prior to 2.13.0
Description The issue is related to uncontrolled resource consumption, where the syntax highlighter fails to limit the size of the code block it processes. This allows an attacker to send a very large code block, potentially crashing the mobile app.
Recommendations For versions prior to 2.13.0, update to version 2.13.0 or later to resolve the issue. As a temporary workaround, consider restricting the size of code blocks that can be processed by the syntax highlighter to prevent excessive resource consumption.

Fix

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2024-24975

Affected Products

Mattermost Mobile