CVE-2024-54083

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Dec 16, 2024
CWE ID 1287

Summary

CVE-2024-54083 is a vulnerability affecting Mattermost versions 10.1.x up to 10.1.2, 10.0.x up to 10.0.2, 9.11.x up to 9.11.4, and 9.5.x up to 9.5.12. This issue arises due to an inadequate validation of callProps in these software versions. A malicious user can exploit this flaw by sending a crafted post and causing a Denial of Service (DoS) on the client side of targeted channels, impacting its users. The vulnerability can affect both the web application and mobile users.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Mattermost Server

Affected Vendors

  • Mattermost, Inc.