cbcvebase.
CVE-2024-4182
published 2024-04-26

CVE-2024-4182: Mattermost versions 9.6.0, 9.5.x before 9.5.3, 9.4.x before 9.4.5, and 8.1.x before 8.1.12 fail to handle JSON parsing errors in custom status values, which…

medium4.3CVSS 3.1
AVNACLPRLUINSUCNINAL
Mattermost versions 9.6.0, 9.5.x before 9.5.3, 9.4.x before 9.4.5, and 8.1.x before 8.1.12 fail to handle JSON parsing errors in custom status values, which allows an authenticated attacker to crash other users' web clients via a malformed custom status.

Affected

16 ranges
VendorProductVersion rangeFixed in
github.commattermost_mattermost-server>= 8.1.0 < 8.1.128.1.12
github.commattermost_mattermost-server>= 8.1.0+incompatible < 8.1.12+incompatible8.1.12+incompatible
github.commattermost_mattermost-server>= 9.4.0 < 9.4.59.4.5
github.commattermost_mattermost-server>= 9.4.0+incompatible < 9.4.5+incompatible9.4.5+incompatible
github.commattermost_mattermost-server>= 9.5.0 < 9.5.39.5.3
github.commattermost_mattermost-server>= 9.5.0+incompatible < 9.5.3+incompatible9.5.3+incompatible
github.commattermost_mattermost-server>= 9.6.0-rc1 < 9.6.19.6.1
github.commattermost_mattermost-server>= 9.6.0-rc1+incompatible < 9.6.1+incompatible9.6.1+incompatible
mattermostmattermost
mattermostmattermost8.1.0 – 8.1.11
mattermostmattermost9.4.0 – 9.4.4
mattermostmattermost9.5.0 – 9.5.2
mattermostmattermost_server>= 8.1.0 < 8.1.128.1.12
mattermostmattermost_server>= 9.4.0 < 9.4.59.4.5
mattermostmattermost_server>= 9.5.0 < 9.5.39.5.3
mattermostmattermost_server>= 9.6.0 < 9.6.19.6.1