CVE-2024-54083
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Dec 16, 2024
CWE ID 1287
Summary
CVE-2024-54083 is a vulnerability affecting Mattermost versions 10.1.x up to 10.1.2, 10.0.x up to 10.0.2, 9.11.x up to 9.11.4, and 9.5.x up to 9.5.12. This issue arises due to an inadequate validation of callProps in these software versions. A malicious user can exploit this flaw by sending a crafted post and causing a Denial of Service (DoS) on the client side of targeted channels, impacting its users. The vulnerability can affect both the web application and mobile users.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Mattermost Server
Affected Vendors
- Mattermost, Inc.