CVE-2024-4182
published 2024-04-26CVE-2024-4182: Mattermost versions 9.6.0, 9.5.x before 9.5.3, 9.4.x before 9.4.5, and 8.1.x before 8.1.12 fail to handle JSON parsing errors in custom status values, which…
PriorityP420medium4.3CVSS 3.1
AVNACLPRLUINSUCNINAL
EPSS
0.55%
42.8th percentile
Mattermost versions 9.6.0, 9.5.x before 9.5.3, 9.4.x before 9.4.5, and 8.1.x before 8.1.12 fail to handle JSON parsing errors in custom status values, which allows an authenticated attacker to crash other users' web clients via a malformed custom status.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | mattermost_mattermost-server | >= 8.1.0 < 8.1.12 | 8.1.12 |
| github.com | mattermost_mattermost-server | >= 8.1.0+incompatible < 8.1.12+incompatible | 8.1.12+incompatible |
| github.com | mattermost_mattermost-server | >= 9.4.0 < 9.4.5 | 9.4.5 |
| github.com | mattermost_mattermost-server | >= 9.4.0+incompatible < 9.4.5+incompatible | 9.4.5+incompatible |
| github.com | mattermost_mattermost-server | >= 9.5.0 < 9.5.3 | 9.5.3 |
| github.com | mattermost_mattermost-server | >= 9.5.0+incompatible < 9.5.3+incompatible | 9.5.3+incompatible |
| github.com | mattermost_mattermost-server | >= 9.6.0-rc1 < 9.6.1 | 9.6.1 |
| github.com | mattermost_mattermost-server | >= 9.6.0-rc1+incompatible < 9.6.1+incompatible | 9.6.1+incompatible |
| mattermost | mattermost | — | — |
| mattermost | mattermost | 8.1.0 – 8.1.11 | — |
| mattermost | mattermost | 9.4.0 – 9.4.4 | — |
| mattermost | mattermost | 9.5.0 – 9.5.2 | — |
| mattermost | mattermost_server | >= 8.1.0 < 8.1.12 | 8.1.12 |
| mattermost | mattermost_server | >= 9.4.0 < 9.4.5 | 9.4.5 |
| mattermost | mattermost_server | >= 9.5.0 < 9.5.3 | 9.5.3 |
| mattermost | mattermost_server | >= 9.6.0 < 9.6.1 | 9.6.1 |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
mattermost: fail to handle JSON parsing errors in custom status values
vendor_redhat·2024-04-26·CVSS 4.3
CVE-2024-4182 [MEDIUM] CWE-754 mattermost: fail to handle JSON parsing errors in custom status values
mattermost: fail to handle JSON parsing errors in custom status values
Mattermost versions 9.6.0, 9.5.x before 9.5.3, 9.4.x before 9.4.5, and 8.1.x before 8.1.12 fail to handle JSON parsing errors in custom status values, which allows an authenticated attacker to crash other users' web clients via a malformed custom status.
A flaw was found in Mattermost, where it fails to handle JSON parsing errors in custom status values. This flaw allows an authenticated attacker to crash other users' web clients via a malformed custom status.
Package: rhacm2/acm-grafana-rhel8 (Red Hat Advanced Cluster Management for Kubernetes 2) - Fix deferred
Package: advanced-cluster-security/rhacs-docs-rhel8 (Red Hat Advanced Cluster Security 3) - Fix deferred
Package: advanced-cluster-security/rhacs-main-rhel
OSV
Mattermost crashes web clients via a malformed custom status in github.com/mattermost/mattermost-server
osv·2024-06-05
CVE-2024-4182 Mattermost crashes web clients via a malformed custom status in github.com/mattermost/mattermost-server
Mattermost crashes web clients via a malformed custom status in github.com/mattermost/mattermost-server
Mattermost crashes web clients via a malformed custom status in github.com/mattermost/mattermost-server
OSV
Mattermost crashes web clients via a malformed custom status
osv·2024-04-26
CVE-2024-4182 [MEDIUM] Mattermost crashes web clients via a malformed custom status
Mattermost crashes web clients via a malformed custom status
Mattermost versions 9.6.0, 9.5.x before 9.5.3, 9.4.x before 9.4.5, and 8.1.x before 8.1.12 fail to handle JSON parsing errors in custom status values, which allows an authenticated attacker to crash other users' web clients via a malformed custom status.
GHSA
Mattermost crashes web clients via a malformed custom status
ghsa·2024-04-26
CVE-2024-4182 [MEDIUM] CWE-754 Mattermost crashes web clients via a malformed custom status
Mattermost crashes web clients via a malformed custom status
Mattermost versions 9.6.0, 9.5.x before 9.5.3, 9.4.x before 9.4.5, and 8.1.x before 8.1.12 fail to handle JSON parsing errors in custom status values, which allows an authenticated attacker to crash other users' web clients via a malformed custom status.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-04-26
Published