Bug 2277342 (CVE-2024-4182) - CVE-2024-4182 mattermost: fail to handle JSON parsing errors in custom status values
Summary: CVE-2024-4182 mattermost: fail to handle JSON parsing errors in custom status...
Keywords:
Status: NEW
Alias: CVE-2024-4182
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2277343 2277344
Blocks: 2277330
TreeView+ depends on / blocked
 
Reported: 2024-04-26 11:57 UTC by Rohit Keshri
Modified: 2024-05-30 22:23 UTC (History)
11 users (show)

Fixed In Version:
Doc Type: ---
Doc Text:
A flaw was found in Mattermost, where it fails to handle JSON parsing errors in custom status values. This flaw allows an authenticated attacker to crash other users' web clients via a malformed custom status.
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Rohit Keshri 2024-04-26 11:57:58 UTC
Mattermost versions 9.6.0, 9.5.x before 9.5.3, 9.4.x before 9.4.5, and 8.1.x before 8.1.12 fail to handle JSON parsing errors in custom status values, which allows an authenticated attacker to crash other users' web clients via a malformed custom status.

https://mattermost.com/security-updates


Note You need to log in before you can comment on or make changes to this bug.