PT-2024-28665 · Mattermost+1 · Mattermost Mobile Apps+1

Juho Forsén

·

Published

2024-07-15

·

Updated

2025-04-11

·

CVE-2024-39767

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Mattermost Mobile Apps versions <=2.16.0
Description The issue allows a malicious server to send push notifications with another server's diagnostic ID or server URL, making them appear as legitimate push notifications from the actual server in mobile apps. This is due to the failure of Mattermost Mobile Apps to validate the source of push notifications.
Recommendations For Mattermost Mobile Apps versions <=2.16.0, update to a version greater than 2.16.0 to resolve the issue.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-3304
CVE-2024-39767

Affected Products

Alt Linux
Mattermost Mobile Apps