ZeroHour

CVE-2024-3872

CVSS 3.1
6.5 medium
EPSS
<1%p39
Published
()
Modified
Description

Mattermost Mobile app versions 2.13.0 and earlier use a regular expression with polynomial complexity to parse certain deeplinks, which allows an unauthenticated remote attacker to freeze or crash the app via a long maliciously crafted link.

Vendors
mattermost
Products
mattermost mobile
Weakness
CWE-400
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.