VYPR
Moderate severityNVD Advisory· Published Feb 29, 2024· Updated Aug 1, 2024

Excessive resource consumption when sending long emoji names in user custom status

CVE-2024-24988

Description

Mattermost fails to properly validate the length of the emoji value in the custom user status, allowing an attacker to send multiple times a very long string as an emoji value causing high resource consumption and possibly crashing the server.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/mattermost/mattermost/server/v8Go
>= 9.3.0, < 9.3.19.3.1
github.com/mattermost/mattermost/server/v8Go
>= 9.2.0, < 9.2.59.2.5

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.