Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS0zMmg3LTdqOTQtOGZjMs4AA5MM

Mattermost vulnerable to denial of service via large number of emoji reactions

Mattermost fails to check if a custom emoji reaction exists when sending it to a post and to limit the amount of custom emojis allowed to be added in a post, allowing an attacker sending a huge amount of non-existent custom emojis in a post to crash the mobile app of a user seeing the post. 

Permalink: https://github.com/advisories/GHSA-32h7-7j94-8fc2
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0zMmg3LTdqOTQtOGZjMs4AA5MM
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: 3 months ago
Updated: 3 months ago


CVSS Score: 4.3
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Identifiers: GHSA-32h7-7j94-8fc2, CVE-2024-1402
References: Repository: https://github.com/mattermost/mattermost
Blast Radius: 0.0

Affected Packages

go:github.com/mattermost/mattermost/server/v8
Dependent packages: 2
Dependent repositories: 1
Downloads:
Affected Version Ranges: >= 9.1.0, < 9.1.5, >= 9.2.0, < 9.2.4, < 8.1.8
Fixed in: 9.1.5, 9.2.4, 8.1.8
All affected versions:
All unaffected versions: