Mattermost versions 9.6.0, 9.5.x before 9.5.3, 9.4.x before 9.4.5, and 8.1.x before 8.1.12 fail to handle JSON parsing errors in custom status values, which allows an authenticated attacker to crash other users' web clients via a malformed custom status.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: Mattermost

Published: 2024-04-26T08:25:37.093Z

Updated: 2024-06-04T17:54:13.942Z

Reserved: 2024-04-25T14:04:51.237Z


Link: CVE-2024-4182

JSON object: View

cve-icon NVD Information

Status : Awaiting Analysis

Published: 2024-04-26T09:15:12.523

Modified: 2024-04-26T12:58:17.720


Link: CVE-2024-4182

JSON object: View

cve-icon Redhat Information

No data.

CWE