CVE-2024-4182

Mattermost versions 9.6.0, 9.5.x before 9.5.3, 9.4.x before 9.4.5, and 8.1.x before 8.1.12 fail to handle JSON parsing errors in custom status values, which allows an authenticated attacker to crash other users' web clients via a malformed custom status.
Configurations

No configuration.

History

21 Nov 2024, 09:42

Type Values Removed Values Added
References () https://mattermost.com/security-updates - () https://mattermost.com/security-updates -
Summary
  • (es) Las versiones Mattermost 9.6.0, 9.5.x anteriores a 9.5.3, 9.4.x anteriores a 9.4.5 y 8.1.x anteriores a 8.1.12 no pueden manejar errores de análisis JSON en valores de estado personalizados, lo que permite que un atacante autenticado se bloquee. clientes web de otros usuarios a través de un estado personalizado con formato incorrecto.

26 Apr 2024, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-26 09:15

Updated : 2024-11-21 09:42


NVD link : CVE-2024-4182

Mitre link : CVE-2024-4182

CVE.ORG link : CVE-2024-4182


JSON object : View

Products Affected

No product.

CWE
CWE-754

Improper Check for Unusual or Exceptional Conditions