CVE-2024-54083
MEDIUMDescription
Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, 9.5.x <= 9.5.12 fail to properly validate the type of callProps which allows a user to cause a client side (webapp and mobile) DoS to users of particular channels, by sending a specially crafted post.
Is your site exposed to CVE-2024-54083?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| mattermost | mattermost_server |
| mattermost | mattermost_server |
| mattermost | mattermost_server |
| mattermost | mattermost_server |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2024-54083? +
How severe is CVE-2024-54083? +
What products are affected by CVE-2024-54083? +
How do I check if I'm vulnerable to CVE-2024-54083? +
Related Vulnerabilities
A security issue exists due to improper handling of CIP Class 32’s request when a module is inhibited on the …
Improper Validation of Specified Type of Input vulnerability in ash-project ash lets an attacker confuse the stored type tag of …
A denial-of-service vulnerability exists in the WebSocket API due to insufficient validation and handling of JSON-based requests. A low-privileged authenticated …
Improper Validation of Specified Type of Input vulnerability in OpenText™ Content Management (Extended ECM) allows Parameter Injection. A bad actor …
github.com/graphql-go/graphql (GraphQL for Go) through 0.8.1 does not validate that a scalar variable value matches its declared type. The built-in …
A security issue exists due to improper handling of CIP Class 32’s request when a module is inhibited on the …