CVE-2024-3872: Medium severity mattermost mobile apps vulnerability
Published Apr 16, 2024
·Updated
Mattermost Mobile app versions 2.13.0 and earlier use a regular expression with polynomial complexity to parse certain deeplinks, which allows an unauthenticated remote attacker to freeze or crash the app via a long maliciously crafted link.
Affected Software
2 affected components
Mattermost Mobile app<2.13.0
Mattermost Mattermost Mobile<=2.13.0
Remediation
Information
Update Mattermost Mobile Apps to versions 2.14.0 or higher.
Event History
Apr 16, 2024
CVE Published
via MITRE·09:05 AM
Data Sourced
via MITRE·09:05 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-3872?
CVE-2024-3872 is categorized as a medium severity vulnerability.
2
How do I fix CVE-2024-3872?
To mitigate CVE-2024-3872, update the Mattermost Mobile app to version 2.13.1 or later.
3
What type of attack is associated with CVE-2024-3872?
CVE-2024-3872 allows unauthenticated remote attackers to freeze or crash the Mattermost Mobile app.
4
Which versions of the Mattermost Mobile app are affected by CVE-2024-3872?
CVE-2024-3872 affects all Mattermost Mobile app versions up to and including 2.13.0.
5
What is the underlying issue in CVE-2024-3872?
CVE-2024-3872 involves a regular expression with polynomial complexity that can be exploited through malicious deeplinks.