CVE-2024-24988
published 2024-02-29CVE-2024-24988: Mattermost fails to properly validate the length of the emoji value in the custom user status, allowing an attacker to send multiple times a very long string…
PriorityP433medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
0.68%
48.6th percentile
Mattermost fails to properly validate the length of the emoji value in the custom user status, allowing an attacker to send multiple times a very long string as an emoji value causing high resource consumption and possibly crashing the server.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | mattermost_mattermost-server | >= 9.2.0+incompatible < 9.2.5+incompatible | 9.2.5+incompatible |
| github.com | mattermost_mattermost-server | >= 9.3.0+incompatible < 9.3.1+incompatible | 9.3.1+incompatible |
| github.com | mattermost_mattermost_server_v8 | >= 9.2.0 < 9.2.5 | 9.2.5 |
| github.com | mattermost_mattermost_server_v8 | >= 9.3.0 < 9.3.1 | 9.3.1 |
| mattermost | mattermost | <= 9.2.4 | — |
| mattermost | mattermost_server | < 8.1.8 | 8.1.8 |
| mattermost | mattermost_server | >= 9.0.0 < 9.1.5 | 9.1.5 |
| mattermost | mattermost_server | >= 9.2.0 < 9.2.4 | 9.2.4 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Mattermost denial of service through long emoji value in github.com/mattermost/mattermost-server
osv·2024-06-28
CVE-2024-24988 Mattermost denial of service through long emoji value in github.com/mattermost/mattermost-server
Mattermost denial of service through long emoji value in github.com/mattermost/mattermost-server
Mattermost denial of service through long emoji value in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.9.
GHSA
Mattermost denial of service through long emoji value
ghsa·2024-02-29
CVE-2024-24988 [MEDIUM] CWE-400 Mattermost denial of service through long emoji value
Mattermost denial of service through long emoji value
Mattermost fails to properly validate the length of the emoji value in the custom user status, allowing an attacker to send multiple times a very long string as an emoji value causing high resource consumption and possibly crashing the server.
OSV
Mattermost denial of service through long emoji value
osv·2024-02-29
CVE-2024-24988 [MEDIUM] Mattermost denial of service through long emoji value
Mattermost denial of service through long emoji value
Mattermost fails to properly validate the length of the emoji value in the custom user status, allowing an attacker to send multiple times a very long string as an emoji value causing high resource consumption and possibly crashing the server.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-02-29
Published