Excessive resource consumption when sending long emoji names in user custom status
Vulnerability Description
Mattermost fails to properly validate the length of the emoji value in the custom user status, allowing an attacker to send multiple times a very long string as an emoji value causing high resource consumption and possibly crashing the server.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-24988
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Gian Klug (coderion)
References
More from Mattermost
View All →Affected Vendor
Mattermost
View all reports →