CVE-2024-1402

Uncontrolled Resource Consumption in go/github.com/mattermost/mattermost/server/v8

Identifiers

GHSA-32h7-7j94-8fc2, CVE-2024-1402

Package Slug

go/github.com/mattermost/mattermost/server/v8

Vulnerability

Uncontrolled Resource Consumption

Description

Mattermost fails to check if a custom emoji reaction exists when sending it to a post and to limit the amount of custom emojis allowed to be added in a post, allowing an attacker sending a huge amount of non-existent custom emojis in a post to crash the mobile app of a user seeing the post. 

Affected Versions

All versions before 8.1.8, all versions starting from 9.1.0 before 9.1.5, all versions starting from 9.2.0 before 9.2.4

Solution

Upgrade to versions 8.1.8, 9.2.4, 9.1.5 or above.

Last Modified

2024-02-12

source